Добавил:
Upload Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
Network Intrusion Detection, Third Edition.pdf
Скачиваний:
213
Добавлен:
15.03.2015
Размер:
2.58 Mб
Скачать

www.hillaryno.com (IP address 206.245.150.74). The supporters of then New York City

mayor Rudolph Giuliani maintained this site. (Mayor Giuliani, at the time of these mysterious occurrences, was an undecided contender for the same seat; he subsequently decided not to run.)

The speculation is that this might have been a cache-poisoning hack that successfully diverted Hillary supporters to the Giuliani page. In other words, www.hillary2000.org was paired

with the IP address for www.hillaryno.com. Of course the people who maintained the www.hillaryno.com site, disavowed all knowledge of any wrongdoing.

So, you see that the arsenal of political dirty tricks has now entered the realm of cyberspace. This would be a very hard kind of hack to trace or prove if the cache were poisoned to reroute users.

Summary

DNS is a distributed hierarchy of name servers that provides different types of resolutions, such as IP addresses and host names. Unlike typical client/server interactions, the resolution of a DNS query might involve multiple DNS servers and multiple connections. And, unlike other client/server interactions, DNS might use UDP, or TCP, or both as the transport protocol to do resolutions.

DNS servers can provide a wealth of reconnaissance information because historically, DNS servers have been the purveyors of host name to IP address pairing information. Sadly, as the Internet has become less safe and less trusted, it is best to silence DNS servers by offering only limited information.

BIND software has a notorious history of security problems. Several exploits have been discovered in recent years that have allowed root level access from buffer overflow attacks. But, it is pretty much impossible to use the Internet today without some kind of interaction with DNS. This doesn't mean that you should innocently trust answers received from other DNS servers, but you should certainly safeguard your own DNS server as much as possible. Upgrade your DNS server to the newest versions, take advantage of the latest security features, and configure your site's DNS servers to restrict the information shared.

Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]