Attacks/Breaches

8/30/2013
06:52 PM
Ehsan Foroughi
Ehsan Foroughi
Commentary
50%
50%

Thwart DNS Hijackers: 5 Tips

Domain name system attacks hit The New York Times and Twitter hard last month. Here are five ways to make your DNS records harder to hack and easier to recover if they're compromised.

The Syrian Electronic Army: 9 Things We Know
(click image for larger view)
The Syrian Electronic Army: 9 Things We Know
In light of the recent domain name system (DNS) hijacking attacks on The New York Times, Twitter and Huffington Post, it's important for CIOs to take a closer look at their DNS security strategy -- and to be able to respond quickly if their company is attacked.

DNS records are basically sets of instructions that help connect your website to the outside world. The following five practices make these records harder to hijack and easier to recover if they are compromised, thereby reducing the damage attackers can cause. When DNS records are hijacked, a company must be able to get them back as quickly as possible because once the malicious records hit the caching servers, it becomes much harder to undo the damage.

1. Use best practices for credentials that allow changes to be made to DNS records.

Your whole service is only as secure as the security of the password to your DNS registrant account. Ensure that access to accounts used to update DNS records is limited to as few people in your organization as possible. Make sure to use hard-to-guess passwords, and avoid reusing passwords at all costs.

[ Here's why you shouldn't buy Android apps from off-brand sites. Read Hack 99% Of Android Devices: Big Vulnerability. ]

2. Revisit the choice of DNS provider regularly as you grow.

Many companies, particularly start-ups, frequently choose DNS registrants and DNS service providers based on a combination of their pricing and the ease of setup and use. Sometimes that means the DNS provider doesn't have much information about the owner other than a username and password used to identify the account. In cases of social engineering attacks or compromised passwords, it might be hard to reclaim the domain.

As companies grow, they should revisit their choice of provider every few months to make sure that it's capable of handling the level of security the company needs. Popular and high-profile services might be targeted by hackers with agendas -- and not every provider is capable of handling the heat that comes with popularity.

3. Make use of SSL certificates.

DNS hijacking can effectively be used to perform man-in-the-middle (MITM) attacks. In a MITM attack, the attacker diverts the user to a malicious server he controls. The malicious server then sends the user's request to the original server and sends the server's response back to the user. This setup allows the attacker to steal the information being passed back and forth, inject malicious content into responses before sending them back to the user, or both.

This is one of the highest risks associated with DNS hijacking and can cause a lot of damage in the form of stolen credentials and injection of malicious content.

To arm yourself, enforce validation of SSL/TLS certificates and use certificate pinning in mobile apps and rich clients. Certificate validation means the attacker must get a certificate tied to the stolen domain before being able to carry out the MITM attack. Pinning certificates in mobile and rich clients will take this restriction even further by ensuring the attacker will need access to the pinned certificate's private keys before being able to carry out the attack. This will reduce the risk of a MITM attack, which means the DNS hijack will do much less prolonged damage.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
3 Ways to Retain Security Operations Staff
Oliver Rochford, Vice President of Security Evangelism at DFLabs,  11/20/2017
A Call for Greater Regulation of Digital Currencies
Kelly Sheridan, Associate Editor, Dark Reading,  11/21/2017
New OWASP Top 10 List Includes Three New Web Vulns
Jai Vijayan, Freelance writer,  11/21/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Managing Cyber-Risk
An online breach could have a huge impact on your organization. Here are some strategies for measuring and managing that risk.
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.