Attacks/Breaches
8/30/2013
06:52 PM
Ehsan Foroughi
Ehsan Foroughi
Commentary
50%
50%

Thwart DNS Hijackers: 5 Tips

Domain name system attacks hit The New York Times and Twitter hard last month. Here are five ways to make your DNS records harder to hack and easier to recover if they're compromised.

The Syrian Electronic Army: 9 Things We Know
(click image for larger view)
The Syrian Electronic Army: 9 Things We Know
In light of the recent domain name system (DNS) hijacking attacks on The New York Times, Twitter and Huffington Post, it's important for CIOs to take a closer look at their DNS security strategy -- and to be able to respond quickly if their company is attacked.

DNS records are basically sets of instructions that help connect your website to the outside world. The following five practices make these records harder to hijack and easier to recover if they are compromised, thereby reducing the damage attackers can cause. When DNS records are hijacked, a company must be able to get them back as quickly as possible because once the malicious records hit the caching servers, it becomes much harder to undo the damage.

1. Use best practices for credentials that allow changes to be made to DNS records.

Your whole service is only as secure as the security of the password to your DNS registrant account. Ensure that access to accounts used to update DNS records is limited to as few people in your organization as possible. Make sure to use hard-to-guess passwords, and avoid reusing passwords at all costs.

[ Here's why you shouldn't buy Android apps from off-brand sites. Read Hack 99% Of Android Devices: Big Vulnerability. ]

2. Revisit the choice of DNS provider regularly as you grow.

Many companies, particularly start-ups, frequently choose DNS registrants and DNS service providers based on a combination of their pricing and the ease of setup and use. Sometimes that means the DNS provider doesn't have much information about the owner other than a username and password used to identify the account. In cases of social engineering attacks or compromised passwords, it might be hard to reclaim the domain.

As companies grow, they should revisit their choice of provider every few months to make sure that it's capable of handling the level of security the company needs. Popular and high-profile services might be targeted by hackers with agendas -- and not every provider is capable of handling the heat that comes with popularity.

3. Make use of SSL certificates.

DNS hijacking can effectively be used to perform man-in-the-middle (MITM) attacks. In a MITM attack, the attacker diverts the user to a malicious server he controls. The malicious server then sends the user's request to the original server and sends the server's response back to the user. This setup allows the attacker to steal the information being passed back and forth, inject malicious content into responses before sending them back to the user, or both.

This is one of the highest risks associated with DNS hijacking and can cause a lot of damage in the form of stolen credentials and injection of malicious content.

To arm yourself, enforce validation of SSL/TLS certificates and use certificate pinning in mobile apps and rich clients. Certificate validation means the attacker must get a certificate tied to the stolen domain before being able to carry out the MITM attack. Pinning certificates in mobile and rich clients will take this restriction even further by ensuring the attacker will need access to the pinned certificate's private keys before being able to carry out the attack. This will reduce the risk of a MITM attack, which means the DNS hijack will do much less prolonged damage.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-1414
Published: 2015-02-27
Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of service (crash) via a crafted IGMP packet, which triggers an incorrect size calculation and allocation of insufficient memory.

CVE-2015-2072
Published: 2015-02-27
Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA 73 (1.00.73.00.389160) and HANA Developer Edition 80 (1.00.80.00.391861) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) ide/core/plugins/editor/templates/trace/hanaTraceDetailService.xsjs or...

CVE-2015-2075
Published: 2015-02-27
SAP BussinessObjects Edge 4.0 allows remote attackers to delete audit events from the auditee queue via a clearData CORBA operation, aka SAP Note 2011396.

CVE-2015-2076
Published: 2015-02-27
The Auditing service in SAP BussinessObjects Edge 4.0 allows remote attackers to obtains sensitive information by reading an audit event, aka SAP Note 2011395.

CVE-2015-2101
Published: 2015-02-27
Cross-site scripting (XSS) vulnerability in the Navigate bar in the Navigate module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.