Close Menu
5gantennas.org5gantennas.org
  • Home
  • 5G
    • 5G Technology
  • 6G
  • AI
  • Data
    • Global 5G
  • Internet
  • WIFI
  • 5G Antennas
  • Legacy

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
5gantennas.org5gantennas.org
  • Home
  • 5G
    1. 5G Technology
    2. View All

    Deutsche Telekom to operate 12,500 5G antennas over 3.6 GHz band

    August 28, 2024

    URCA Releases Draft “Roadmap” for 5G Rollout in the Bahamas – Eye Witness News

    August 23, 2024

    Smart Launches Smart ZTE Blade A75 5G » YugaTech

    August 22, 2024

    5G Drone Integration Denmark – DRONELIFE

    August 21, 2024

    Hughes praises successful private 5G demo for U.S. Navy

    August 29, 2024

    GSA survey reveals 5G FWA has become “mainstream”

    August 29, 2024

    China Mobile expands 5G Advanced, Chunghwa Telecom enters Europe

    August 29, 2024

    Ateme and ORS Boost 5G Broadcast Capacity with “World’s First Trial of IP-Based Statmux over 5G Broadcast” | TV Tech

    August 29, 2024
  • 6G

    India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

    August 29, 2024

    Vodafonewatch Weekly: Rural 4G, Industrial 5G, 6G Patents | Weekly Briefing

    August 29, 2024

    Southeast Asia steps up efforts to build 6G standards

    August 29, 2024

    Energy efficiency as an inherent attribute of 6G networks

    August 29, 2024

    Finnish working group launches push for 6G technology

    August 28, 2024
  • AI

    Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

    August 29, 2024

    Why Honeywell is betting big on Gen AI

    August 29, 2024

    Ethically questionable or creative genius? How artists are engaging with AI in their work | Art and Design

    August 29, 2024

    “Elon Musk and Trump” arrested for burglary in disturbing AI video

    August 29, 2024

    Nvidia CFO says ‘enterprise AI wave’ has begun and Fortune 100 companies are leading the way

    August 29, 2024
  • Data
    1. Global 5G
    2. View All

    Global 5G Enterprise Market is expected to be valued at USD 34.4 Billion by 2032

    August 12, 2024

    Counterpoint predicts 5G will dominate the smartphone market in early 2024

    August 5, 2024

    Qualcomm’s new chipsets will power affordable 5G smartphones

    July 31, 2024

    Best Super Fast Download Companies — TradingView

    July 31, 2024

    Crypto Markets Rise on Strong US Economic Data

    August 29, 2024

    Microsoft approves construction of third section of Mount Pleasant data center campus

    August 29, 2024

    China has invested $6.1 billion in state-run data center projects over two years, with the “East Data, West Computing” initiative aimed at capitalizing on the country’s untapped land.

    August 29, 2024

    What is the size of the clinical data analysis solutions market?

    August 29, 2024
  • Internet

    NATO believes Russia poses a threat to Western internet and GPS services

    August 29, 2024

    Mpeppe grows fast, building traction among Internet computer owners

    August 29, 2024

    Internet Computer Whale Buys Mpeppe (MPEPE) at 340x ROI

    August 29, 2024

    Long-term internet computer investor adds PEPE rival to holdings

    August 29, 2024

    Biden-Harris Administration Approves Initial Internet for All Proposals in Mississippi and South Dakota

    August 29, 2024
  • WIFI

    4 Best Wi-Fi Mesh Networking Systems in 2024

    September 6, 2024

    Best WiFi deal: Save $200 on the Starlink Standard Kit AX

    August 29, 2024

    Sonos Roam 2 review | Good Housekeeping UK

    August 29, 2024

    Popular WiFi extender that eliminates dead zones in your home costs just $12

    August 29, 2024

    North American WiFi 6 Mesh Router Market Size, Share, Forecast, [2030] – அக்னி செய்திகள்

    August 29, 2024
  • 5G Antennas

    Nokia and Claro bring 5G to Argentina

    August 27, 2024

    Nokia expands FWA portfolio with new 5G devices – SatNews

    July 25, 2024

    Deutsche Telekom to operate 12,150 5G antennas over 3.6 GHz band

    July 24, 2024

    Vodafone and Ericsson develop a compact 5G antenna in Germany

    July 12, 2024

    Vodafone and Ericsson unveil new small antennas to power Germany’s 5G network

    July 11, 2024
  • Legacy
5gantennas.org5gantennas.org
Home»Internet»Thanks to DNSSEC, just one malformed packet can bring down a vulnerable DNS server.
Internet

Thanks to DNSSEC, just one malformed packet can bring down a vulnerable DNS server.

5gantennas.orgBy 5gantennas.orgFebruary 13, 2024No Comments6 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email


By exploiting a more than 20-year-old design flaw in the DNSSEC specification, a single packet can exhaust the processing power of a vulnerable DNS server, effectively disabling the machine.

That way, it’s easy to take down a DNSSEC-validating DNS resolver that hasn’t yet been patched, disrupting all clients that rely on that service and making your website or app appear as if it were offline. I can see it.

The academics who discovered the flaw are associated with the German National Center for Applied Cybersecurity Research (ATHENE) in Darmstadt, and when briefed on the vulnerability, the DNS server software maker called the flaw one of the most It claimed to be the worst DNS attack of all time.

It was identified by Professor Haya Schulman and Niklas Vogel of Goethe University Frankfurt. Elias Heftrig of Fraunhofer SIT. The security hole, named his KeyTrap and designated CVE-2023-50387, was assigned a CVSS severity rating of 7.5 out of 10, according to Professor Michael Waidner of Darmstadt University of Technology and Fraunhofer SIT and colleagues.

As of December 2023, approximately 31% of web clients worldwide use DNSSEC-validating DNS resolvers and, like other applications that rely on these systems, can be susceptible to KeyTrap attacks. there is. When these DNS servers are disabled due to defects, clients rely on DNS resolvers. Domain names and host names cannot be resolved to IP addresses and connectivity is lost.

Researchers found that a single DNS packet that exploits KeyTrap can bring down DNSSEC-verified public DNS services provided by Google and Cloudflare by forcing servers to perform calculations that overload their CPU cores. He said that there is a sex.

Not only can this DNS disruption deny people access to content, but it can also interfere with other systems such as spam protection, cryptographic protection (PKI), and interdomain routing security (RPKI). researchers claim.

“If exploited, this attack would severely impact any application that uses the Internet, including disabling technologies such as web browsing, email, and instant messaging,” they claimed. “KeyTrap allows attackers to completely disable large portions of the world’s Internet.”

Non-public technical documentation regarding vulnerabilities provided to registerThe article entitled “KeyTrap Denial of Service Algorithm Complexity Attack on DNS” describes how the attack is carried out. Basically, you ask a vulnerable DNSSEC-validating DNS resolver to look up an address, the server connects to a malicious name server, and the resolver sends a response that consumes most or all of its own CPU resources. Masu.

KeyTrap could allow attackers to completely disable large parts of the world’s internet

“To launch the attack, the adversary forces the victim’s resolver to search for records in the malicious domain,” the paper, which will be published soon, states. “The attacker’s name server responds to her DNS queries with a malicious record set (RRset) according to the specific attack vector and zone configuration.”

This attack is possible because the DNSSEC specification follows Postel’s Law, which states that “a name server should send all available cryptographic material, and a resolver should use any cryptographic material it receives until verification is successful.” The paper explains that it works.

This requirement to ensure availability means that DNSSEC validating DNS resolvers can be forced to do more work if there are key tags and key collisions that need to be validated.

“Our complexity attack is triggered by feeding DNS resolvers with specially crafted DNSSEC records that are constructed in a way that exploits validation vulnerabilities in the cryptographic validation logic,” the paper explains. Masu.

“When DNS resolvers try to validate the DNSSEC records they receive from our name servers, they hang up. Our attack is very stealthy, and a single DNS response can take a resolver anywhere from 170 seconds to 16 hours (depending on the resolver software. packet. “

ATHENE officials said they worked with all relevant vendors and major public DNS providers to privately disclose the vulnerability and allow for a coordinated patch release. The last patch was completed today.

“We are aware of this vulnerability and have worked with the researchers who reported it to deploy a fix,” a Google spokesperson said. register. “At this time, there is no evidence of exploitation and no action is required from users.”

Networking research institute NLnet Labs has released a patch for its Unbound DNS software that addresses two vulnerabilities, one of which is KeyTrap. Another fixed bug, CVE-2023-50868, called the NSEC3 vulnerability, also allows for denial of service due to CPU exhaustion.

“The KeyTrap vulnerability works by using a combination of keys (even colliding keys), signatures, and RRSET numbers on the malicious zone,” NLnet Labs wrote. “Responses from that zone can force the DNSSEC validator to go through a very CPU-intensive and time-consuming validation path.”

Meanwhile, PowerDNS has an update here to stop KeyTrap exploits.

“An attacker could expose a zone that contains crafted DNSSEC-related records. When validating the results of queries to that zone using RFC-mandated algorithms, Recursor’s resource usage could be reduced. could become very high, impacting the processing of other queries, and potentially causing a denial of service,” the team wrote. “Please note that resolvers that comply with the RFC may be affected; this is not an issue with this particular implementation.”

The CVE-2023-50387 fix is ​​just one of six vulnerabilities addressed in the Internet Systems Consortium’s BIND 9 DNS software. Others include:

  • CVE-2023-4408: Parsing large DNS messages can cause excessive CPU load.
  • CVE-2023-5517: When ‘nxdomain-redirect’ is enabled, querying an RFC 1918 reverse zone can result in an assertion failure.
  • CVE-2023-5679: Enabling both DNS64 and serve-stale can result in an assertion failure during recursive resolution.
  • CVE-2023-6516: Certain recursive query patterns can lead to an out-of-memory condition.
  • CVE-2023-50868: Preparing NSEC3 nearest neighbor proofs can exhaust CPU resources.

According to the research team that identified the KeyTrap vulnerability, the requirements for the KeyTrap vulnerability date back to 1999 in the now-obsolete RFC 2535. And by 2012, these elements appeared in RFC 6781 and RFC 6840, implementation requirements for DNSSEC validation.

1 pack is enough.You don’t need to do anything more to disconnect your entire network

KeyTrap has been present in the BIND 9 DNS resolver since at least August 2000 (over 23 years ago) and appeared in the Unbound DNS resolver seven years later.

“We’re thrilled to be able to provide the most advanced technology in the world,” said Dr. Haya Schulman, a professor of computer science and one of the academics supporting the KeyTrap research. register For telephone interviews, the attack is simple and can be performed by encoding it into a zone file.

“This vulnerability is actually recommended by the DNSSEC standard,” Professor Schulman explained. “One packet is enough; you don’t need to do more to disconnect the entire network.”

Professor Shulman said patches issued by various vendors broke standards. “The problem is that this attack is not easy to solve,” she says. “When I launch against the patched resolver, the CPU usage is 100%, but it is still responsive.”

The ATHENE team observed that although this flaw went undetected for decades, its obscurity is not surprising since DNSSEC validation requirements are so complex. The same goes for mitigating vulnerabilities, which would require revisions to the DNSSEC standard to completely eliminate them. ®



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThousands lose power and internet after truck crashes into power pole in Charlottesville
Next Article Why top AI stock C3.ai fell on Tuesday
5gantennas.org
  • Website

Related Posts

NATO believes Russia poses a threat to Western internet and GPS services

August 29, 2024

Mpeppe grows fast, building traction among Internet computer owners

August 29, 2024

Internet Computer Whale Buys Mpeppe (MPEPE) at 340x ROI

August 29, 2024
Leave A Reply Cancel Reply

You must be logged in to post a comment.

Latest Posts

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024

Crypto Markets Rise on Strong US Economic Data

August 29, 2024
Don't Miss

Business News | Communications Minister Scindia promotes 6G leadership and nationwide broadband in meeting with telecom operators

By 5gantennas.orgAugust 24, 2024

New Delhi [India]August 24 (ANI): Union Telecom Minister Jyotiraditya Scindia along with Minister of State…

SingTel and SK Telecom prepare for the 6G future

July 8, 2024

Apple focuses on 6G for future iPhones

December 11, 2023

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to 5GAntennas.org, your reliable source for comprehensive information on 5G technology, artificial intelligence (AI), and data-related advancements. We are passionate about staying at the forefront of these cutting-edge fields and bringing you the latest insights, trends, and developments.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024
Most Popular

Will 5G make 2024 the most connected year in the industry?

December 1, 2023

The current state of 5G in the US and how it can improve

September 28, 2023

How 5G technology will transform gaming on the go

January 31, 2024
© 2025 5gantennas. Designed by 5gantennas.
  • Home
  • About us
  • Contact us
  • DMCA
  • Privacy Policy
  • About Creator

Type above and press Enter to search. Press Esc to cancel.