NXNSAttack ื‘ืึทืคืึทืœืŸ ื•ื•ืึธืก ืึทืคืขืงืฅ ืึทืœืข ื“ื ืก ืจืขืกืึธืœื•ื•ืขืจืก

ื ื’ืจื•ืคึผืข ืคื•ืŸ โ€‹โ€‹ืคืึธืจืฉืขืจ ืคื•ืŸ ืชืœ ืื‘ื™ื‘ ืื•ื ื™ื•ื•ืขืจืกื™ื˜ืขื˜ ืื•ืŸ ื“ืขื ื™ื ื˜ืขืจื“ื™ืกืฆื™ืคึผืœื™ืŸ ืฆืขื ื˜ืขืจ ืื™ืŸ ื”ืจืฆืœื™ื” (ื™ืฉืจืืœ) ื”ืื˜ ื“ืขื•ื•ืขืœืึธืคึผืขื“ ื ื™ื™ึท ื‘ืึทืคืึทืœืŸ ืื•ืคึฟืŸ NXNSAttack (ืคึผื“ืฃ), ืึทืœืึทื•ื™ื ื’ ืื™ืจ ืฆื• ื ื•ืฆืŸ ืงื™ื™ืŸ DNS ืจืขืกืึธืœื•ื•ืขืจื– ื•ื•ื™ ืคืึทืจืงืขืจ ืึทืžืคึผืœืึทืคื™ื™ืขืจื–, ืคึผืจืึทื•ื•ื™ื™ื“ื™ื ื’ ืึท ืึทืžืคึผืœืึทืคืึทืงื™ื™ืฉืึทืŸ ืงื•ืจืก ืคื•ืŸ ืึทืจื•ื™ืฃ ืฆื• 1621 ืžืึธืœ ืื™ืŸ ื˜ืขืจืžื™ื ืขืŸ ืคื•ืŸ ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ืคึผืึทืงื™ืฅ (ืคึฟืึทืจ ื™ืขื“ืขืจ ื‘ืขื˜ืŸ ื’ืขืฉื™ืงื˜ ืฆื• ื“ื™ ืจืขืกืึธืœื•ื•ืขืจ, ืื™ืจ ืงืขื ืขืŸ ื“ืขืจื’ืจื™ื™ื›ืŸ 1621 ืจื™ืงื•ื•ืขืก ืฆื• ื“ื™ ืกืขืจื•ื•ืขืจ ืคื•ืŸ ื“ื™ ืงืึธืจื‘ืŸ) ืื•ืŸ ืึทืจื•ื™ืฃ ืฆื• 163 ืžืืœ ืื™ืŸ ื˜ืขืจืžื™ื ืขืŸ ืคื•ืŸ ืคืึทืจืงืขืจ.

ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ืฉื™ื™ึทื›ื•ืช ืฆื• ื“ื™ ืคึผื™ืงื™ื•ืœื™ืขืจืึทื˜ื™ื– ืคื•ืŸ ื“ืขื ืคึผืจืึธื˜ืึธืงืึธืœ ืื•ืŸ ืึทืคืขืงืฅ ืึทืœืข ื“ื ืก ืกืขืจื•ื•ืขืจืก ื•ื•ืึธืก ืฉื˜ื™ืฆืŸ ืจืขืงื•ืจืกื™ื•ื•ืข ืึธื ืคึฟืจืขื’ ืคึผืจืึทืกืขืกื™ื ื’, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ BIND (CVE-2020-8616) ืงื ืึธื˜ (CVE-2020-12667) ืคึผืึธื•ื•ืขืจื“ื ืก (CVE-2020-10995) Windows DNS ืกืขืจื•ื•ื™ืจืขืจ ะธ ื•ื ื‘ืึธื•ื ื“ (CVE-2020-12662), ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ืขืคื ื˜ืœืขืš ื“ื ืก ื‘ืึทื“ื™ื ื•ื ื’ืก ืคื•ืŸ Google, Cloudflare, Amazon, Quad9, ICANN ืื•ืŸ ืื ื“ืขืจืข ืงืึธืžืคึผืึทื ื™ืขืก. ื“ื™ ืคืึทืจืจื™ื›ื˜ืŸ ืื™ื– ืงืึธื•ืึธืจื“ืึทื ื™ื™ื˜ื™ื“ ืžื™ื˜ ื“ื ืก ืกืขืจื•ื•ืขืจ ื“ืขื•ื•ืขืœืึธืคึผืขืจืก, ื•ื•ืึธืก ืกื™ื™ืžืึทืœื˜ื™ื™ื ื™ืึทืกืœื™ ื‘ืืคืจื™ื™ื˜ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืฆื• ืคืึทืจืจื™ื›ื˜ืŸ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื–ื™ื™ืขืจ ืคึผืจืึธื“ื•ืงื˜ืŸ. ื‘ืึทืคืึทืœืŸ ืฉื•ืฅ ื™ืžืคึผืœืึทืžืขื ืึทื“ ืื™ืŸ ืจื™ืœื™ืกื™ื–
ื ื™ื˜ ื’ืขื‘ื•ื ื“ืŸ 1.10.1, ืงื ืึธื˜ ืจืขืกืึธืœื•ื•ืขืจ 5.1.1, PowerDNS ืจืขืงื•ืจืกืึธืจ 4.3.1, 4.2.2, 4.1.16, ื‘ื™ื ื“ 9.11.19, 9.14.12, 9.16.3.

ื“ื™ ื‘ืึทืคืึทืœืŸ ืื™ื– ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ ืึทื˜ืึทืงืขืจ ื ื™ืฆืŸ ืจื™ืงื•ื•ืขืก ื•ื•ืึธืก ืึธืคึผืฉื™ืงืŸ ืฆื• ืึท ื’ืจื•ื™ืก ื ื•ืžืขืจ ืคื•ืŸ ื‘ื™ื– ืึทื”ืขืจ ื•ืžื‘ืึทืžืขืจืงื˜ ืคื™ืงื˜ื™ื˜ื™ืึธื•ืก ื ืก ืจืขืงืึธืจื“ืก, ืฆื• ื•ื•ืึธืก ื ืึธืžืขืŸ ืคืขืกื˜ืงื™ื™ึทื˜ ืื™ื– ื“ืขืœืึทื’ื™ื™ื˜ืึทื“, ืึธื‘ืขืจ ืึธืŸ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืงืœื™ื™ ืจืขืงืึธืจื“ืก ืžื™ื˜ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ IP ืึทื“ืจืขืกืขืก ืคื•ืŸ ื ืก ืกืขืจื•ื•ืขืจืก ืื™ืŸ ื“ืขืจ ืขื ื˜ืคืขืจ. ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ืึท ืึทื˜ืึทืงืขืจ ืกืขื ื“ื– ืึท ืึธื ืคึฟืจืขื’ ืฆื• ื‘ืึทืฉืœื™ืกืŸ ื“ื™ ื ืึธืžืขืŸ sd1.attacker.com ื“ื•ืจืš ืงืึทื ื˜ืจืึธื•ืœื™ื ื’ ื“ื™ ื“ื ืก ืกืขืจื•ื•ืขืจ ืคืึทืจืึทื ื˜ื•ื•ืึธืจื˜ืœืขืš ืคึฟืึทืจ ื“ื™ attacker.com ืคืขืœื“. ืื™ืŸ ืขื ื˜ืคืขืจ ืฆื• ื“ื™ ื‘ืงืฉื” ืคื•ืŸ ื“ื™ ืจืขืกืึธืœื•ื•ืขืจ ืฆื• ื“ื™ ื“ื ืก ืกืขืจื•ื•ืขืจ ืคื•ืŸ ื“ื™ ืึทื˜ืึทืงืขืจ, ืึท ืขื ื˜ืคืขืจ ืื™ื– ืืจื•ื™ืก ื•ื•ืึธืก ื“ืขืœืึทื’ื™ื™ืฅ ื“ื™ ื‘ืึทืฉื˜ื™ืžื•ื ื’ ืคื•ืŸ ื“ื™ sd1.attacker.com ืึทื“ืจืขืก ืฆื• ื“ื™ ื“ื ืก ืกืขืจื•ื•ืขืจ ืคื•ืŸ ื“ื™ ืงืึธืจื‘ืŸ ื“ื•ืจืš ื™ื ื“ืึทืงื™ื™ื˜ื™ื ื’ NS ืจืขืงืึธืจื“ืก ืื™ืŸ ื“ืขืจ ืขื ื˜ืคืขืจ ืึธืŸ ื“ื™ื˜ื™ื™ืœื™ื ื’ ื“ื™ IP ื ืก ืกืขืจื•ื•ืขืจืก. ื–ื™ื ื˜ ื“ื™ ื“ืขืจืžืื ื˜ NS ืกืขืจื•ื•ืขืจ ืื™ื– ื ื™ืฉื˜ ื’ืขืคึผืœืึธื ื˜ืขืจื˜ ืคืจื™ืขืจ ืื•ืŸ ื–ื™ื™ืŸ IP ืึทื“ืจืขืก ืื™ื– ื ื™ืฉื˜ ืกืคึผืขืกื™ืคื™ืขื“, ื“ืขืจ ืจืขืกืึธืœื•ื•ืขืจ ืคืจื•ื•ื•ื˜ ืฆื• ื‘ืึทืฉืœื™ืกืŸ ื“ื™ IP ืึทื“ืจืขืก ืคื•ืŸ ื“ื™ NS ืกืขืจื•ื•ืขืจ ื“ื•ืจืš ืฉื™ืงืŸ ืึท ืึธื ืคึฟืจืขื’ ืฆื• ื“ื™ ืงืึธืจื‘ืŸ ืก ื“ื ืก ืกืขืจื•ื•ืขืจ ืกืขืจื•ื•ื™ื ื’ ื“ื™ ืฆื™ืœ ืคืขืœื“ (victim.com).

NXNSAttack ื‘ืึทืคืึทืœืŸ ื•ื•ืึธืก ืึทืคืขืงืฅ ืึทืœืข ื“ื ืก ืจืขืกืึธืœื•ื•ืขืจืก

ื“ื™ ืคึผืจืึธื‘ืœืขื ืื™ื– ืึทื– ื“ืขืจ ืึทื˜ืึทืงืขืจ ืงืขื ืขืŸ ืจื™ืกืคึผืึทื ื“ ืžื™ื˜ ืึท ืจื™ื–ื™ืง ืจืฉื™ืžื” ืคื•ืŸ ื ื™ื˜-ืจื™ืคึผื™ื˜ื™ื ื’ ื ืก ืกืขืจื•ื•ืขืจืก ืžื™ื˜ ื ื™ื˜-ืขื’ื–ื™ืกื˜ืึทื ื˜ ืคื™ืงื˜ื™ืฉืึทืก ืงืึธืจื‘ืŸ ืกื•ื‘ื“ืึธืžืึทื™ืŸ ื ืขืžืขืŸ (ืคืึทืงืข-1.victim.com, fake-2.victim.com, ... fake-1000. victim.com). ื“ืขืจ ืจืขืกืึธืœื•ื•ืขืจ ื•ื•ืขื˜ ืคึผืจื•ื‘ื™ืจืŸ ืฆื• ืฉื™ืงืŸ ืึท ื‘ืงืฉื” ืฆื• ื“ื™ ื“ื ืก ืกืขืจื•ื•ืขืจ ืคื•ืŸ ื“ื™ ืงืึธืจื‘ืŸ, ืึธื‘ืขืจ ื•ื•ืขื˜ ื‘ืึทืงื•ืžืขืŸ ืึท ืขื ื˜ืคืขืจ ืึทื– ื“ื™ ืคืขืœื“ ืื™ื– ื ื™ืฉื˜ ื’ืขืคื•ื ืขืŸ, ื ืึธืš ื•ื•ืึธืก ืขืก ื•ื•ืขื˜ ืคึผืจื•ื‘ื™ืจืŸ ืฆื• ื‘ืึทืฉืœื™ืกืŸ ื“ื™ ื•ื•ื™ื™ึทื˜ืขืจ ื ืก ืกืขืจื•ื•ืขืจ ืื™ืŸ ื“ืขืจ ืจืฉื™ืžื”, ืื•ืŸ ืึทื–ื•ื™ ืื•ื™ืฃ ื‘ื™ื– ืขืจ ื”ืื˜ ื’ืขืคืจื•ื•ื•ื˜ ืึทืœืข ื“ื™ NS ืจืขืงืึธืจื“ืก ืœื™ืกื˜ืขื“ ื“ื•ืจืš ื“ื™ ืึทื˜ืึทืงืขืจ. ืึทืงืงืึธืจื“ื™ื ื’ืœื™, ืคึฟืึทืจ ืื™ื™ืŸ ืึทื˜ืึทืงืขืจ ืก ื‘ืงืฉื”, ื“ืขืจ ืจืขืกืึธืœื•ื•ืขืจ ื•ื•ืขื˜ ืฉื™ืงืŸ ืึท ืจื™ื–ื™ืง ื ื•ืžืขืจ ืคื•ืŸ ืจื™ืงื•ื•ืขืก ืฆื• ื‘ืึทืฉืœื™ืกืŸ NS ืžื—ื ื•ืช. ื–ื™ื ื˜ NS ืกืขืจื•ื•ืขืจ ื ืขืžืขืŸ ื–ืขื ืขืŸ ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ืจืึทื ื“ืึทืžืœื™ ืื•ืŸ ืึธืคึผืฉื™ืงืŸ ืฆื• ื ื™ื˜-ืขื’ื–ื™ืกื˜ืึทื ื˜ ืกื•ื‘ื“ืึธืžืึทื™ื ืก, ื–ื™ื™ ื–ืขื ืขืŸ ื ื™ืฉื˜ ืจื™ื˜ืจื™ื•ื•ื“ ืคื•ืŸ ื“ื™ ืงืึทืฉ ืื•ืŸ ื™ืขื“ืขืจ ื‘ืงืฉื” ืคื•ืŸ ื“ื™ ืึทื˜ืึทืงืขืจ ืจืขื–ื•ืœื˜ืื˜ืŸ ืื™ืŸ ืึท ืคืœืขืจื™ ืคื•ืŸ ืจื™ืงื•ื•ืขืก ืฆื• ื“ื™ ื“ื ืก ืกืขืจื•ื•ืขืจ ืกืขืจื•ื•ื™ื ื’ ื“ื™ ืงืึธืจื‘ืŸ ืก ืคืขืœื“.

NXNSAttack ื‘ืึทืคืึทืœืŸ ื•ื•ืึธืก ืึทืคืขืงืฅ ืึทืœืข ื“ื ืก ืจืขืกืึธืœื•ื•ืขืจืก

ืจืขืกืขืึทืจื˜ืฉืขืจืก ื’ืขืœืขืจื ื˜ ื“ื™ ื’ืจืึทื“ ืคื•ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืคื•ืŸ ืฆื™ื‘ื•ืจ ื“ื ืก ืจืขืกืึธืœื•ื•ืขืจื– ืฆื• ื“ืขื ืคึผืจืึธื‘ืœืขื ืื•ืŸ ื‘ืืฉืœืืกืŸ ืึทื– ื•ื•ืขืŸ ืฉื™ืงื˜ ืคึฟืจืื’ืŸ ืฆื• ื“ื™ CloudFlare ืจืขืกืึธืœื•ื•ืขืจ (1.1.1.1), ืขืก ืื™ื– ืžืขื’ืœืขืš ืฆื• ืคืึทืจื’ืจืขืกืขืจืŸ ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ืคึผืึทืงื™ืฅ (PAF, ืคึผืึทืงืึทื˜ ืึทืžืคึผืœืึทืคืึทืงื™ื™ืฉืึทืŸ ืคืึทืงื˜ืึธืจ) ืžื™ื˜ 48 ืžืืœ, Google (8.8.8.8) - 30 ืžืืœ, FreeDNS (37.235.1.174) - 50 ืžืืœ, OpenDNS (208.67.222.222) - 32 ืžืืœ. ืžืขืจ ื‘ืืžืขืจืงื˜ ื™ื ื“ื™ืงืึทื˜ืึธืจืก ื–ืขื ืขืŸ ื‘ืืžืขืจืงื˜ ืคึฟืึทืจ
ืœืขื•ื•ืขืœ3 (209.244.0.3) - 273 ืžืืœ, ืงื•ื•ืึทื“9 (9.9.9.9) - 415 ืžืืœ
ืกืึทืคืขื“ื ืก (195.46.39.39) - 274 ืžืืœ, ื•ื•ืขืจื™ืกื™ื’ืŸ (64.6.64.6) - 202 ืžืืœ,
ืึทืœื˜ืจืึท (156.154.71.1) - 405 ืžืืœ, ืงืึธืžืึธื“ืึธ ืกืขืงื•ืจืข (8.26.56.26) - 435 ืžืืœ, DNS.Watch (84.200.69.80) - 486 ืžืืœ, ืื•ืŸ Norton ConnectSafe (199.85.126.10 ืžืืœ) - 569 ืžืืœ. ืคึฟืึทืจ ืกืขืจื•ื•ืขืจืก ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ BIND 9.12.3, ืจืขื›ื˜ ืฆื• ืคึผืึทืจืึทืœืขืœื™ื–ืึทื˜ื™ืึธืŸ ืคื•ืŸ ืจื™ืงื•ื•ืขืก, ื“ื™ ื’ืขื•ื•ื™ื ืก ืžื“ืจื’ื” ืงืขื ืขืŸ ื“ืขืจื’ืจื™ื™ื›ืŸ ืึทืจื•ื™ืฃ ืฆื• 1000. ืื™ืŸ Knot Resolver 5.1.0, ื“ื™ ื’ืขื•ื•ื™ื ืก ืžื“ืจื’ื” ืื™ื– ื‘ืขืขืจืขืš ืขื˜ืœืขื›ืข ื˜ืขื ืก ืคื•ืŸ ืžืืœ (24-48), ื–ื™ื ื˜ ื“ื™ ืคืขืกื˜ืงื™ื™ึทื˜ ืคื•ืŸ NS ื ืขืžืขืŸ ืื™ื– ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืกืึทืงื•ื•ืขื ื˜ืฉืึทืœื™ ืื•ืŸ ืจืขืกืฅ ืื•ื™ืฃ ื“ื™ ื™ื ืขืจืœืขืš ืฉื™ืขื•ืจ ืื•ื™ืฃ ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ื ืึธืžืขืŸ ื”ืึทื›ืœืึธื˜ืข ืกื˜ืขืคึผืก ืขืจืœื•ื™ื‘ื˜ ืคึฟืึทืจ ืื™ื™ืŸ ื‘ืงืฉื”.

ืขืก ื–ืขื ืขืŸ ืฆื•ื•ื™ื™ ื”ื•ื™ืคึผื˜ ืคืึทืจื˜ื™ื™ื“ื™ืงื•ื ื’ ืกื˜ืจืึทื˜ืขื’ื™ืขืก. ืคึฟืึทืจ ืกื™ืกื˜ืขืžืขืŸ ืžื™ื˜ DNSSEC ืคืืจื’ืขืœื™ื™ื’ื˜ ื ื•ืฆืŸ ืจืคืง-8198 ืฆื• ืคืึทืจืžื™ื™ึทื“ืŸ ื“ื ืก ืงืึทืฉ ื‘ื™ื™ืคึผืึทืก ื•ื•ื™ื™ึทืœ ืจื™ืงื•ื•ืขืก ื–ืขื ืขืŸ ื’ืขืฉื™ืงื˜ ืžื™ื˜ ื˜ืจืึทืค ื ืขืžืขืŸ. ื“ื™ ืขืกืึทื ืก ืคื•ืŸ ื“ืขื ืื•ืคึฟืŸ ืื™ื– ืฆื• ื“ื–ืฉืขื ืขืจื™ื™ื˜ ื ืขื’ืึทื˜ื™ื•ื• ืจืขืกืคึผืึธื ืกืขืก ืึธืŸ ืงืึธื ื˜ืึทืงื˜ ืึทื˜ืึธืจืึทื˜ื™ื™ื˜ื™ื•ื• ื“ื ืก ืกืขืจื•ื•ืขืจืก, ื ื™ืฆืŸ ืงื™ื™ื˜ ืงืึธื ื˜ืจืึธืœื™ืจื•ื ื’ ื“ื•ืจืš DNSSEC. ื ืกื™ืžืคึผืœืขืจ ืฆื•ื’ืึทื ื’ ืื™ื– ืฆื• ื‘ืึทื’ืจืขื ืขืฆืŸ ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ื ืขืžืขืŸ ื•ื•ืึธืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื“ื™ืคื™ื™ื ื“ ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ืึท ืื™ื™ืŸ ื“ืขืœืึทื’ื™ื™ื˜ืึทื“ ื‘ืขื˜ืŸ, ืึธื‘ืขืจ ื“ืขื ืื•ืคึฟืŸ ืงืขืŸ ืคืึทืจืฉืึทืคืŸ ืคึผืจืึธื‘ืœืขืžืก ืžื™ื˜ ืขื˜ืœืขื›ืข ื™ื’ื–ื™ืกื˜ื™ื ื’ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทื ื– ื•ื•ื™ื™ึทืœ ื“ื™ ืœื™ืžืึทืฅ ื–ืขื ืขืŸ ื ื™ืฉื˜ ื“ื™ืคื™ื™ื ื“ ืื™ืŸ ื“ืขื ืคึผืจืึธื˜ืึธืงืึธืœ.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’