ื”ืชืงืคืช NXNSAttack ื”ืžืฉืคื™ืขื” ืขืœ ื›ืœ ืคื•ืชืจื™ ื”-DNS

ืงื‘ื•ืฆืช ื—ื•ืงืจื™ื ืžืื•ื ื™ื‘ืจืกื™ื˜ืช ืชืœ ืื‘ื™ื‘ ื•ืžื”ืžืจื›ื– ื”ื‘ื™ื ืชื—ื•ืžื™ ื‘ื”ืจืฆืœื™ื” (ื™ืฉืจืืœ) ื”ืชืคืชื— ืฉื™ื˜ืช ื”ืชืงืคื” ื—ื“ืฉื” NXNSAtack (PDF), ื”ืžืืคืฉืจ ืœืš ืœื”ืฉืชืžืฉ ื‘ื›ืœ ืกื•ืœื‘ืจ DNS ื›ืžื’ื‘ืจื™ ืชืขื‘ื•ืจื”, ืชื•ืš ืžืชืŸ ืงืฆื‘ ื”ื’ื‘ืจื” ืฉืœ ืขื“ ืคื™ 1621 ืžื‘ื—ื™ื ืช ืžืกืคืจ ื”ื—ื‘ื™ืœื•ืช (ืขื‘ื•ืจ ื›ืœ ื‘ืงืฉื” ืฉื ืฉืœื—ืช ืœืคื•ืชืจ, ืชื•ื›ืœ ืœื”ืฉื™ื’ 1621 ื‘ืงืฉื•ืช ืฉื ืฉืœื—ื•ืช ืœืฉืจืช ืฉืœ ื”ืงื•ืจื‘ืŸ) ื•ืขื“ ืคื™ 163 ืžื‘ื—ื™ื ืช ืชืขื‘ื•ืจื”.

ื”ื‘ืขื™ื” ืงืฉื•ืจื” ืœืžื•ื–ืจื•ื™ื•ืช ืฉืœ ื”ืคืจื•ื˜ื•ืงื•ืœ ื•ืžืฉืคื™ืขื” ืขืœ ื›ืœ ืฉืจืชื™ ื”-DNS ื”ืชื•ืžื›ื™ื ื‘ืขื™ื‘ื•ื“ ืฉืื™ืœืชื•ืช ืจืงื•ืจืกื™ื‘ื™, ื›ื•ืœืœ BIND (CVE-2020-8616) ืงืฉืจ (CVE-2020-12667) PowerDNS (CVE-2020-10995) ืฉืจืช DNS ืฉืœ Windows ะธ unbound (CVE-2020-12662), ื›ืžื• ื’ื ืฉื™ืจื•ืชื™ DNS ืฆื™ื‘ื•ืจื™ื™ื ืฉืœ ื’ื•ื’ืœ, Cloudflare, Amazon, Quad9, ICANN ื•ื—ื‘ืจื•ืช ื ื•ืกืคื•ืช. ื”ืชื™ืงื•ืŸ ืชื•ืื ืขื ืžืคืชื—ื™ ืฉืจืชื™ DNS, ืฉืคืจืกืžื• ื‘ื• ื–ืžื ื™ืช ืขื“ื›ื•ื ื™ื ืœืชื™ืงื•ืŸ ื”ืคื’ื™ืขื•ืช ื‘ืžื•ืฆืจื™ื ืฉืœื”ื. ื”ื’ื ืช ืชืงื™ืคื” ืžื™ื•ืฉืžืช ื‘ืžื”ื“ื•ืจื•ืช
ืœื ืงืฉื•ืจ 1.10.1, ืคืชืจื•ืŸ ืงืฉืจื™ื 5.1.1, PowerDNS Recursor 4.3.1, 4.2.2, 4.1.16, BIND 9.11.19, 9.14.12, 9.16.3.

ื”ื”ืชืงืคื” ืžืชื‘ืกืกืช ืขืœ ืฉื™ืžื•ืฉ ื‘ื‘ืงืฉื•ืช ื”ืžืชื™ื™ื—ืกื•ืช ืœืžืกืคืจ ืจื‘ ืฉืœ ืจืฉื•ืžื•ืช NS ืคื™ืงื˜ื™ื‘ื™ื•ืช ืฉืœื ื ืจืื• ื‘ืขื‘ืจ, ืืœื™ื”ืŸ ืžื•ืืฆืœืช ืงื‘ื™ืขืช ืฉืžื•ืช, ืืš ืœืœื ืฆื™ื•ืŸ ืจืฉื•ืžื•ืช ื“ื‘ืง ืขื ืžื™ื“ืข ืขืœ ื›ืชื•ื‘ื•ืช ื”-IP ืฉืœ ืฉืจืชื™ NS ื‘ืชื’ื•ื‘ื”. ืœื“ื•ื’ืžื”, ืชื•ืงืฃ ืฉื•ืœื— ืฉืื™ืœืชื” ื›ื“ื™ ืœืคืชื•ืจ ืืช ื”ืฉื sd1.attacker.com ืขืœ ื™ื“ื™ ืฉืœื™ื˜ื” ื‘ืฉืจืช ื”-DNS ื”ืื—ืจืื™ ืขืœ ื”ืชื—ื•ื attacker.com. ื‘ืชื’ื•ื‘ื” ืœื‘ืงืฉืช ื”ืคื•ืชืจ ืœืฉืจืช ื”-DNS ืฉืœ ื”ืชื•ืงืฃ, ื™ื•ืฆืืช ืชื’ื•ื‘ื” ื”ืžืืฆื™ืœื” ืืช ืงื‘ื™ืขืช ื”ื›ืชื•ื‘ืช sd1.attacker.com ืœืฉืจืช ื”-DNS ืฉืœ ื”ืงื•ืจื‘ืŸ ืขืœ ื™ื“ื™ ืฆื™ื•ืŸ ืจืฉื•ืžื•ืช NS ื‘ืชื’ื•ื‘ื” ืžื‘ืœื™ ืœืคืจื˜ ืืช ืฉืจืชื™ ื”-IP NS. ืžืื—ืจ ืฉืฉืจืช ื”-NS ื”ืžื•ื–ื›ืจ ืœื ื ืชืงืœ ื‘ืขื‘ืจ ื•ื›ืชื•ื‘ืช ื”-IP ืฉืœื• ืœื ืฆื•ื™ื ื”, ื”ืคื•ืชืจ ืžื ืกื” ืœืงื‘ื•ืข ืืช ื›ืชื•ื‘ืช ื”-IP ืฉืœ ืฉืจืช ื”-NS ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ืฉืื™ืœืชื” ืœืฉืจืช ื”-DNS ืฉืœ ื”ืงื•ืจื‘ืŸ ื”ืžืฉืจืช ืืช ื“ื•ืžื™ื™ืŸ ื”ื™ืขื“ (victim.com).

ื”ืชืงืคืช NXNSAttack ื”ืžืฉืคื™ืขื” ืขืœ ื›ืœ ืคื•ืชืจื™ ื”-DNS

ื”ื‘ืขื™ื” ื”ื™ื ืฉื”ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ื’ื™ื‘ ืขื ืจืฉื™ืžื” ืขื ืงื™ืช ืฉืœ ืฉืจืชื™ NS ืฉืื™ื ื ื—ื•ื–ืจื™ื ืขืœ ืขืฆืžื ืขื ืฉืžื•ืช ืชืช-ื“ื•ืžื™ื™ืŸ ืคื™ืงื˜ื™ื‘ื™ื™ื ืฉืœ ืงื•ืจื‘ื ื•ืช (fake-1.victim.com, fake-2.victim.com,... fake-1000. victim.com). ื”ืคื•ืชืจ ื™ื ืกื” ืœืฉืœื•ื— ื‘ืงืฉื” ืœืฉืจืช ื”-DNS ืฉืœ ื”ื ืคื’ืข, ืืš ื™ืงื‘ืœ ืชืฉื•ื‘ื” ืฉื”ื“ื•ืžื™ื™ืŸ ืœื ื ืžืฆื, ื•ืœืื—ืจ ืžื›ืŸ ื™ื ืกื” ืœืงื‘ื•ืข ืืช ืฉืจืช ื”-NS ื”ื‘ื ื‘ืจืฉื™ืžื”, ื•ื›ืŸ ื”ืœืื” ืขื“ ืฉื™ื ืกื” ืืช ื›ืœ ืจืฉื•ืžื•ืช NS ื”ืจืฉื•ืžื•ืช ืขืœ ื™ื“ื™ ื”ืชื•ืงืฃ. ื‘ื”ืชืื, ืขื‘ื•ืจ ื‘ืงืฉื” ืฉืœ ืชื•ืงืฃ ืื—ื“, ื”ืคื•ืชืจ ื™ืฉืœื— ืžืกืคืจ ืขืฆื•ื ืฉืœ ื‘ืงืฉื•ืช ืœืงื‘ื™ืขืช ืžืืจื—ื™ NS. ืžื›ื™ื•ื•ืŸ ืฉืฉืžื•ืช ืฉืจืชื™ NS ื ื•ืฆืจื™ื ื‘ืื•ืคืŸ ืืงืจืื™ ื•ืžืชื™ื™ื—ืกื™ื ืœืชืช-ื“ื•ืžื™ื™ื ื™ื ืฉืื™ื ื ืงื™ื™ืžื™ื, ื”ื ืื™ื ื ื ืฉืœืคื™ื ืžื”ืžื˜ืžื•ืŸ ื•ื›ืœ ื‘ืงืฉื” ืžื”ืชื•ืงืฃ ืžื‘ื™ืื” ืœืฉื˜ืฃ ืฉืœ ื‘ืงืฉื•ืช ืœืฉืจืช ื”-DNS ื”ืžืฉืจืช ืืช ื”ื“ื•ืžื™ื™ืŸ ืฉืœ ื”ืงื•ืจื‘ืŸ.

ื”ืชืงืคืช NXNSAttack ื”ืžืฉืคื™ืขื” ืขืœ ื›ืœ ืคื•ืชืจื™ ื”-DNS

ื—ื•ืงืจื™ื ื‘ื—ื ื• ืืช ืžื™ื“ืช ื”ืคื’ื™ืขื•ืช ืฉืœ ืคื•ืชืจื™ DNS ืฆื™ื‘ื•ืจื™ื™ื ืœื‘ืขื™ื” ื•ืงื‘ืขื• ื›ื™ ื‘ืขืช ืฉืœื™ื—ืช ืฉืื™ืœืชื•ืช ืœืคื•ืชืจ CloudFlare (1.1.1.1), ื ื™ืชืŸ ืœื”ื’ื“ื™ืœ ืืช ืžืกืคืจ ื”ื—ื‘ื™ืœื•ืช (PAF, Packet Amplification Factor) ืคื™ 48, ื’ื•ื’ืœ. (8.8.8.8) - 30 ืคืขืžื™ื, FreeDNS (37.235.1.174) - 50 ืคืขืžื™ื, OpenDNS (208.67.222.222) - 32 ืคืขืžื™ื. ืื™ื ื“ื™ืงื˜ื•ืจื™ื ื‘ื•ืœื˜ื™ื ื™ื•ืชืจ ื ืฆืคื™ื ืขื‘ื•ืจ
Level3 (209.244.0.3) - 273 ืคืขืžื™ื, Quad9 (9.9.9.9) - 415 ืคืขืžื™ื
SafeDNS (195.46.39.39) - 274 ืคืขืžื™ื, Verisign (64.6.64.6) - 202 ืคืขืžื™ื,
Ultra (156.154.71.1) - 405 ืคืขืžื™ื, Comodo Secure (8.26.56.26) - 435 ืคืขืžื™ื, DNS.Watch (84.200.69.80) - 486 ืคืขืžื™ื, ื•-Norton ConnectSafe (199.85.126.10 ืคืขืžื™ื) - 569 ืคืขืžื™ื. ืขื‘ื•ืจ ืฉืจืชื™ื ื”ืžื‘ื•ืกืกื™ื ืขืœ BIND 9.12.3, ืขืงื‘ ื”ืงื‘ื™ืœื” ืฉืœ ื‘ืงืฉื•ืช, ืจืžืช ื”ื”ื’ื‘ืจ ื™ื›ื•ืœื” ืœื”ื’ื™ืข ืขื“ 1000. ื‘- Knot Resolver 5.1.0, ืจืžืช ื”ื”ื’ื‘ืจ ื”ื™ื ื‘ืขืจืš ื›ืžื” ืขืฉืจื•ืช ืคืขืžื™ื (24-48), ืžืื– ืงื‘ื™ืขืช ืฉืžื•ืช NS ืžื‘ื•ืฆืขื™ื ื‘ืจืฆืฃ ื•ื ืฉืขื ื™ื ืขืœ ื”ืžื’ื‘ืœื” ื”ืคื ื™ืžื™ืช ืฉืœ ืžืกืคืจ ืฉืœื‘ื™ ืคืชืจื•ืŸ ื”ืฉืžื•ืช ื”ืžื•ืชืจื™ื ืขื‘ื•ืจ ื‘ืงืฉื” ืื—ืช.

ื™ืฉื ืŸ ืฉืชื™ ืืกื˜ืจื˜ื’ื™ื•ืช ื”ื’ื ื” ืขื™ืงืจื™ื•ืช. ืœืžืขืจื›ื•ืช ืขื DNSSEC ืžื•ึผืฆึธืข ืฉื™ืžื•ืฉ RFC-8198 ื›ื“ื™ ืœืžื ื•ืข ืขืงื™ืคืช ืžื˜ืžื•ืŸ DNS ืžื›ื™ื•ื•ืŸ ืฉื‘ืงืฉื•ืช ื ืฉืœื—ื•ืช ืขื ืฉืžื•ืช ืืงืจืื™ื™ื. ืžื”ื•ืช ื”ืฉื™ื˜ื” ื”ื™ื ืœื™ืฆื•ืจ ืชื’ื•ื‘ื•ืช ืฉืœื™ืœื™ื•ืช ืžื‘ืœื™ ืœื™ืฆื•ืจ ืงืฉืจ ืขื ืฉืจืชื™ DNS ืกืžื›ื•ืชื™ื™ื, ื‘ืืžืฆืขื•ืช ื‘ื“ื™ืงืช ื˜ื•ื•ื— ื“ืจืš DNSSEC. ื’ื™ืฉื” ืคืฉื•ื˜ื” ื™ื•ืชืจ ื”ื™ื ืœื”ื’ื‘ื™ืœ ืืช ืžืกืคืจ ื”ืฉืžื•ืช ืฉื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ื‘ืขืช ืขื™ื‘ื•ื“ ื‘ืงืฉื” ืžื•ืืฆืœืช ื‘ื•ื“ื“ืช, ืืš ืฉื™ื˜ื” ื–ื• ืขืœื•ืœื” ืœื’ืจื•ื ืœื‘ืขื™ื•ืช ื‘ื›ืžื” ืชืฆื•ืจื•ืช ืงื™ื™ืžื•ืช ืžื›ื™ื•ื•ืŸ ืฉื”ืžื’ื‘ืœื•ืช ืื™ื ืŸ ืžื•ื’ื“ืจื•ืช ื‘ืคืจื•ื˜ื•ืงื•ืœ.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”