{"id":102308,"date":"2021-11-17T21:36:54","date_gmt":"2021-11-17T19:36:54","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/novyj-variant-ataki-sad-dns-dlya-podstanovki-fiktivnyh-dannyh-v-kesh-dns"},"modified":"2021-11-17T21:36:54","modified_gmt":"2021-11-17T19:36:54","slug":"novyj-variant-ataki-sad-dns-dlya-podstanovki-fiktivnyh-dannyh-v-kesh-dns","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/novyj-variant-ataki-sad-dns-dlya-podstanovki-fiktivnyh-dannyh-v-kesh-dns","title":{"rendered":"Nuova variante dell'attacco SAD DNS per l'inserimento di dati falsi nella cache DNS","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Un gruppo di ricercatori dell'Universit\u00e0 della California a Riverside ha pubblicato una nuova variante dell'attacco SAD DNS (CVE-2021-20322), che funziona nonostante la protezione aggiunta lo scorso anno per bloccare la vulnerabilit\u00e0 CVE-2020-25705. Il nuovo metodo \u00e8 in generale analogo alla vulnerabilit\u00e0 dello scorso anno e si differenzia solo per l'uso di un altro tipo di pacchetti ICMP per controllare le porte UDP attive. L'attacco proposto consente l'inserimento di dati falsi nella cache del server DNS, il che pu\u00f2 essere utilizzato per sostituire l'indirizzo IP di un dominio qualsiasi nella cache e reindirizzare le richieste al dominio verso un server malintenzionato.      <\/p>\n<p>Il metodo proposto \u00e8 operativo solo nello stack di rete Linux a causa del legame con una caratteristica del meccanismo di elaborazione dei pacchetti ICMP in Linux, che funge da fonte di fuga di dati, semplificando l'identificazione del numero di porta UDP utilizzato. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/it\/server\/dts-prohoster\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3026\">server<\/a> per inviare richieste esterne. Le modifiche che bloccano le perdite di informazioni sono state integrate nel kernel di Linux alla fine di agosto (la correzione \u00e8 stata inclusa nel kernel 5.15 e negli aggiornamenti di settembre delle branche LTS del kernel). La correzione consiste nel passaggio all'uso dell'algoritmo di hashing SipHash nei cache di rete invece di Jenkins Hash. Lo stato di risoluzione della vulnerabilit\u00e0 nelle distribuzioni pu\u00f2 essere valutato sulle seguenti pagine: Debian, RHEL, Fedora, SUSE, Ubuntu.     <\/p>\n<p>Secondo i ricercatori che hanno identificato il problema, circa il 38% dei resolver aperti disponibili su Internet \u00e8 vulnerabile, inclusi servizi DNS popolari come OpenDNS e Quad9 (9.9.9.9). Per quanto riguarda il software del server, l'attacco pu\u00f2 essere effettuato utilizzando su un server Linux pacchetti come BIND, Unbound e dnsmasq. Nei server DNS eseguiti su Windows e sistemi BSD, il problema non si manifesta. Per portare a termine con successo l'attacco, \u00e8 necessario utilizzare lo spoofing IP, quindi il provider dell'attaccante non deve bloccare i pacchetti con un indirizzo IP di origine falsificato.      <\/p>\n<p>Ricordiamo che l'attacco SAD DNS consente di eludere la protezione implementata nei server DNS per bloccare il classico metodo di avvelenamento della cache DNS, proposto nel 2008 da Dan Kaminsky. Il metodo di Kaminsky manipola la dimensione ridotta del campo riguardante il numero identificativo della richiesta DNS, che \u00e8 di soli 16 bit. Per trovare il corretto identificatore della transazione DNS necessario per lo spoofing del nome host, \u00e8 sufficiente inviare circa 7000 richieste e simulare circa 140.000 risposte fittizie. L'attacco consiste nell'inviare al risolutore DNS un numero elevato di pacchetti con un'associazione IP fittizia e con identificatori di transazione DNS differenti. Per prevenire la memorizzazione nella cache della prima risposta, in ogni risposta fittizia viene indicato un nome di dominio leggermente modificato (1.example.com, 2.example.com, 3.example.com e cos\u00ec via).     <\/p>\n<p>Per proteggersi da questo tipo di attacco, i produttori di server DNS hanno implementato una distribuzione casuale dei numeri delle porte di rete sorgente da cui vengono inviati i richieste di risoluzione, il che ha compensato la dimensione insufficiente dell'identificatore. Dopo l'implementazione della protezione, per inviare una risposta fasulla \u00e8 diventato necessario scegliere non solo un identificatore a 16 bit, ma anche una delle 64.000 porte, aumentando cos\u00ec il numero di varianti da ricercare fino a 2^32.    <\/p>\n<p>Il metodo SAD DNS semplifica notevolmente la determinazione del numero della porta di rete e riduce l'attacco al classico metodo di Kaminsky. L'attaccante pu\u00f2 identificare l'accesso a porte UDP non utilizzate e attive, sfruttando la fuga di informazioni sull'attivit\u00e0 delle porte di rete durante l'elaborazione delle risposte ai pacchetti ICMP. Questo metodo consente di ridurre di 4 ordini di grandezza il numero di varianti da esaminare \u2014 2^16+2^16 invece di 2^32 (131_072 invece di 4_294_967_296). La fuga di informazioni che permette di identificare rapidamente le porte UDP attive \u00e8 causata da una mancanza nel codice di gestione dei pacchetti ICMP riguardanti le richieste di frammentazione (flag ICMP Fragmentation Needed) o di reindirizzamento (flag ICMP Redirect). L'invio di tali pacchetti modifica lo stato della cache nello stack di rete, consentendo, sulla base della reazione del server, di determinare quale delle porte UDP sia attiva e quale no.    <\/p>\n<p>Scenario di attacco: Quando un risolutore DNS tenta di determinare un nome di dominio, invia una richiesta UDP al server DNS che gestisce il dominio. Nel momento in cui il risolutore attende una risposta, l'attaccante pu\u00f2 rapidamente determinare il numero della porta di origine utilizzata per inviare la richiesta e inviare una risposta fasulla, spacciandosi per il server DNS che gestisce il dominio, utilizzando lo spoofing. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/it\/lir\/ipv4\/\"   title=\"Indirizzi IP\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"694\">Indirizzi IP<\/a>Il risolutore DNS memorizzer\u00e0 nella cache i dati inoltrati nella risposta fasulla e per un certo periodo restituir\u00e0 l'indirizzo IP sostituito dall'attaccante per tutte le altre richieste DNS del nome di dominio.<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=56176\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u041a\u0430\u043b\u0438\u0444\u043e\u0440\u043d\u0438\u0439\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0432 \u0420\u0438\u0432\u0435\u0440\u0441\u0430\u0439\u0434\u0435 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u043d\u043e\u0432\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u0430\u0442\u0430\u043a\u0438 SAD DNS (CVE-2021-20322), \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0439 \u043d\u0435\u0441\u043c\u043e\u0442\u0440\u044f \u043d\u0430 \u0437\u0430\u0449\u0438\u0442\u0443, \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u043d\u0443\u044e \u0432 \u043f\u0440\u043e\u0448\u043b\u043e\u043c \u0433\u043e\u0434\u0443 \u0434\u043b\u044f \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 CVE-2020-25705. \u041d\u043e\u0432\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u0432 \u0446\u0435\u043b\u043e\u043c \u0430\u043d\u0430\u043b\u043e\u0433\u0438\u0447\u0435\u043d \u043f\u0440\u043e\u0448\u043b\u043e\u0433\u043e\u0434\u043d\u0435\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0438 \u043e\u0442\u043b\u0438\u0447\u0430\u0435\u0442\u0441\u044f \u043b\u0438\u0448\u044c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u0434\u0440\u0443\u0433\u043e\u0433\u043e \u0442\u0438\u043f\u0430 ICMP-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0430\u043a\u0442\u0438\u0432\u043d\u044b\u0445 UDP-\u043f\u043e\u0440\u0442\u043e\u0432. \u041f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043d\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0438\u0442\u044c \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 \u0444\u0438\u043a\u0442\u0438\u0432\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u043a\u044d\u0448 DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u0430, \u0447\u0442\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-102308","post","type-post","status-publish","format-standard","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u041a\u0430\u043b\u0438\u0444\u043e\u0440\u043d\u0438\u0439\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0432 \u0420\u0438\u0432\u0435\u0440\u0441\u0430\u0439\u0434\u0435 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u043d\u043e\u0432\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u0430\u0442\u0430\u043a\u0438 SAD DNS (CVE-2021-20322), \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0439 \u043d\u0435\u0441\u043c\u043e\u0442\u0440\u044f \u043d\u0430 \u0437\u0430\u0449\u0438\u0442\u0443, \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u043d\u0443\u044e \u0432 \u043f\u0440\u043e\u0448\u043b\u043e\u043c \u0433\u043e\u0434\u0443 \u0434\u043b\u044f \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 CVE-2020-25705. \u041d\u043e\u0432\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u0432 \u0446\u0435\u043b\u043e\u043c \u0430\u043d\u0430\u043b\u043e\u0433\u0438\u0447\u0435\u043d \u043f\u0440\u043e\u0448\u043b\u043e\u0433\u043e\u0434\u043d\u0435\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0438 \u043e\u0442\u043b\u0438\u0447\u0430\u0435\u0442\u0441\u044f \u043b\u0438\u0448\u044c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u0434\u0440\u0443\u0433\u043e\u0433\u043e \u0442\u0438\u043f\u0430 ICMP-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0430\u043a\u0442\u0438\u0432\u043d\u044b\u0445 UDP-\u043f\u043e\u0440\u0442\u043e\u0432. \u041f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043d\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0438\u0442\u044c \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 \u0444\u0438\u043a\u0442\u0438\u0432\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u043a\u044d\u0448 DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u0430, \u0447\u0442\u043e\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/novyj-variant-ataki-sad-dns-dlya-podstanovki-fiktivnyh-dannyh-v-kesh-dns\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041d\u043e\u0432\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u0430\u0442\u0430\u043a\u0438 SAD DNS \u0434\u043b\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0444\u0438\u043a\u0442\u0438\u0432\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u043a\u044d\u0448 DNS | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u041a\u0430\u043b\u0438\u0444\u043e\u0440\u043d\u0438\u0439\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0432 \u0420\u0438\u0432\u0435\u0440\u0441\u0430\u0439\u0434\u0435 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u043d\u043e\u0432\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u0430\u0442\u0430\u043a\u0438 SAD DNS (CVE-2021-20322), \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0439 \u043d\u0435\u0441\u043c\u043e\u0442\u0440\u044f \u043d\u0430 \u0437\u0430\u0449\u0438\u0442\u0443, \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u043d\u0443\u044e \u0432 \u043f\u0440\u043e\u0448\u043b\u043e\u043c \u0433\u043e\u0434\u0443 \u0434\u043b\u044f \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 CVE-2020-25705. \u041d\u043e\u0432\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u0432 \u0446\u0435\u043b\u043e\u043c \u0430\u043d\u0430\u043b\u043e\u0433\u0438\u0447\u0435\u043d \u043f\u0440\u043e\u0448\u043b\u043e\u0433\u043e\u0434\u043d\u0435\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0438 \u043e\u0442\u043b\u0438\u0447\u0430\u0435\u0442\u0441\u044f \u043b\u0438\u0448\u044c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u0434\u0440\u0443\u0433\u043e\u0433\u043e \u0442\u0438\u043f\u0430 ICMP-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0430\u043a\u0442\u0438\u0432\u043d\u044b\u0445 UDP-\u043f\u043e\u0440\u0442\u043e\u0432. \u041f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043d\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0438\u0442\u044c \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 \u0444\u0438\u043a\u0442\u0438\u0432\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u043a\u044d\u0448 DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u0430, \u0447\u0442\u043e\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/novyj-variant-ataki-sad-dns-dlya-podstanovki-fiktivnyh-dannyh-v-kesh-dns\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-11-17T19:36:54+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-11-17T19:36:54+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Nuova variante dell'attacco SAD DNS per l'inserimento di dati fittizi nella cache DNS | ProHoster","description":"Un gruppo di ricercatori dell'Universit\u00e0 della California a Riverside ha pubblicato una nuova variante dell'attacco SAD DNS (CVE-2021-20322), che funziona nonostante le protezioni aggiunte l'anno scorso per bloccare la vulnerabilit\u00e0 CVE-2020-25705. Il nuovo metodo \u00e8 nel complesso simile alla vulnerabilit\u00e0 dell'anno scorso e si distingue solo per l'uso di un altro tipo di pacchetti ICMP per controllare le porte UDP attive. L'attacco proposto consente l'inserimento di dati fittizi nella cache del server DNS, il che","canonical_url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/novyj-variant-ataki-sad-dns-dlya-podstanovki-fiktivnyh-dannyh-v-kesh-dns","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041d\u043e\u0432\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u0430\u0442\u0430\u043a\u0438 SAD DNS \u0434\u043b\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u0444\u0438\u043a\u0442\u0438\u0432\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u043a\u044d\u0448 DNS | ProHoster","og:description":"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u041a\u0430\u043b\u0438\u0444\u043e\u0440\u043d\u0438\u0439\u0441\u043a\u043e\u0433\u043e \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0438\u0442\u0435\u0442\u0430 \u0432 \u0420\u0438\u0432\u0435\u0440\u0441\u0430\u0439\u0434\u0435 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u043d\u043e\u0432\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u0430\u0442\u0430\u043a\u0438 SAD DNS (CVE-2021-20322), \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0439 \u043d\u0435\u0441\u043c\u043e\u0442\u0440\u044f \u043d\u0430 \u0437\u0430\u0449\u0438\u0442\u0443, \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u043d\u0443\u044e \u0432 \u043f\u0440\u043e\u0448\u043b\u043e\u043c \u0433\u043e\u0434\u0443 \u0434\u043b\u044f \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 CVE-2020-25705. \u041d\u043e\u0432\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u0432 \u0446\u0435\u043b\u043e\u043c \u0430\u043d\u0430\u043b\u043e\u0433\u0438\u0447\u0435\u043d \u043f\u0440\u043e\u0448\u043b\u043e\u0433\u043e\u0434\u043d\u0435\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0438 \u043e\u0442\u043b\u0438\u0447\u0430\u0435\u0442\u0441\u044f \u043b\u0438\u0448\u044c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u0434\u0440\u0443\u0433\u043e\u0433\u043e \u0442\u0438\u043f\u0430 ICMP-\u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0430\u043a\u0442\u0438\u0432\u043d\u044b\u0445 UDP-\u043f\u043e\u0440\u0442\u043e\u0432. \u041f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043d\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0438\u0442\u044c \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 \u0444\u0438\u043a\u0442\u0438\u0432\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u043a\u044d\u0448 DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u0430, \u0447\u0442\u043e","og:url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/novyj-variant-ataki-sad-dns-dlya-podstanovki-fiktivnyh-dannyh-v-kesh-dns","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-11-17T19:36:54+00:00","article:modified_time":"2021-11-17T19:36:54+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"102308","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-11-17 19:38:17","updated":"2026-02-09 21:46:42","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/102308","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=102308"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/102308\/revisions"}],"predecessor-version":[{"id":160307,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/102308\/revisions\/160307"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=102308"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=102308"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=102308"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}