Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

DNS Alerts-as-a-Service

New DNS alert service lets organizations customize, control notification of DNS problems and vulnerabilities

Jun 24, 2008 | 07:40 AM

By Kelly Jackson Higgins
DarkReading

Plenty of Websites have incorrect Domain Name Service (DNS) settings, but their owners typically don’t find out until it’s too late and their servers stop responding, or get hacked. DNSstuff.com is now offering a round-the-clock DNS alert service that lets organizations fine-tune automatic notifications of their DNS-related problems.

“There’s not a lot of knowledge around DNS in the enterprise. That’s one of the key reasons we preconfigure and solve these problems for you,” says Rich Person, CEO of DNSstuff.com, which in a recent user survey found that nearly 70 percent of active domains are configured incorrectly.

DNS servers are prone to vulnerabilities, mainly due to human error in configuring them. They also are prone to hacks, such as attacker breaking into a registrar account and changing the name servers to which the domain is attached.

“The number of vulnerabilities is increasing daily. There are a lot of opportunities to subvert DNS... and then it can compromise a host file, too,” says Paul Parisi, CTO of DNSstuff.com.

The new version of DNSalerts also provides instructions for fixing the problems it spots, Parisi says, and eventually will add a Wiki-based knowledge base.

DNS inventor Paul Mockapetris says the DNSstuff service is an easy alternative to doing it yourself. “DNSStuff's offering basically costs the same as an hour or two of your highest level sysadmin's time, and works 24/7, and has the external viewing done, and is slicker than what you could roll on your own,” says Mockapetris, chief scientist and chairman of the board for network naming and address vendor Nominum. “It's not free, but it's cheap, easy, and effective.”

The DNSalerts 2.0 service is priced at $99 a year per domain.

— Kelly Jackson Higgins, Senior Editor, Dark Reading

  • DNSstuff.com
  • Nominum Inc.


  • Subscribe to RSS










    Bugs
    ENTERPRISE VULNERABILITIES
    Vulnerability:suse linux
    Published:2010-01-22
    Severity:High
    Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
    Vulnerability:bind
    Published:2010-01-22
    Severity:Medium
    Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


    Briefing Centers
    POWERFUL INFORMATION
    AT YOUR FINGERTIPS
    (SPONSORED LINKS)