DNSSEC under attack? | Internet News

DNSSEC under attack?

Nov 25, 2009
1 minute read

security-200x180-redlock_small.jpg

From the

Mission Accomplished

?

files:

For more than a year now I’ve heard lots of people in the Internet industry proclaiming DNSSEC (DNS Security Extensions) as the long-term solution to DNS cache poisoning vulnerabilities.

That may not necessarily be the case.

A new vulnerability is now out that attacks DNS servers  WITH DNSSSEC installed.

In the summer of 2008, security researcher Dan Kaminsky made the whole world aware of potential security issues with DNS, which could have undermined the integrity of the Internet itself. DNSSEC is supposed to be answer, with most of the world’s major Internet registries moving to implement the technology.

So what’s up with this new attack? For one, it specifically deals with the ISC BIND 9 DNS server which is widely deployed.

“A nameserver with DNSSEC validation enabled may incorrectly add records
to its cache from the additional section of responses received during
resolution of a recursive client query,” the security advisory from ISC states. “This behavior only occurs when
processing client queries with checking disabled (CD) at the same time
as requesting DNSSEC records (DO).”

So to recap. DNSSEC, the same tech that is supposed to help prevent DNS cache poisoning could itself be poisoned in certain circumstances.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.