<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ruan Müller &#187; dns</title>
	<atom:link href="http://ruanmuller.com/tag/dns/feed/" rel="self" type="application/rss+xml" />
	<link>http://ruanmuller.com</link>
	<description>Willing and not afraid to challenge the status quo.</description>
	<lastBuildDate>Wed, 14 Dec 2011 19:57:11 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>New DoS Vulnerability Affects All Versions of BIND 9</title>
		<link>http://ruanmuller.com/2009/07/29/new-dos-vulnerability-affects-all-versions-of-bind-9/</link>
		<comments>http://ruanmuller.com/2009/07/29/new-dos-vulnerability-affects-all-versions-of-bind-9/#comments</comments>
		<pubDate>Wed, 29 Jul 2009 17:35:30 +0000</pubDate>
		<dc:creator>Ruan</dc:creator>
				<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[BIND]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[DOS]]></category>

		<guid isPermaLink="false">http://ruanmuller.com/?p=301</guid>
		<description><![CDATA[ISC is reporting that a new, remotely exploitable vulnerability has been found in all versions of BIND 9. A specially crafted dynamic update packet will make BIND die with an assertion error. There is an exploit in the wild and there are no access control workarounds. Red Hat claims that the exploit does not affect [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p><em>ISC is reporting that a new, remotely exploitable <a href="https://www.isc.org/node/474">vulnerability has been found in all versions of BIND 9</a>. A specially crafted dynamic update packet will make BIND die with an assertion error. There is an exploit in the wild and there are no access control workarounds. <a href="https://bugzilla.redhat.com/show_bug.cgi?id=514292">Red Hat claims</a> that the exploit does not affect BIND servers that do not allow dynamic updates, but the ISC post refutes that. This is a high-priority vulnerability and DNS operators will want to upgrade BIND to the latest patch level.</em></p></blockquote>
<p>Via: <a href="http://it.slashdot.org/story/09/07/29/0028231/New-DoS-Vulnerability-In-All-Versions-of-BIND-9">Slashdot</a></p>
<div class="social_bookmark"><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://ruanmuller.com/2009/07/29/new-dos-vulnerability-affects-all-versions-of-bind-9/&amp;title=New+DoS+Vulnerability+Affects+All+Versions+of+BIND+9" title="Add 'New DoS Vulnerability Affects All Versions of BIND 9' to digg"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/digg.png" title="Add 'New DoS Vulnerability Affects All Versions of BIND 9' to digg" alt="Add 'New DoS Vulnerability Affects All Versions of BIND 9' to digg" border="0" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?title=New+DoS+Vulnerability+Affects+All+Versions+of+BIND+9&amp;url=http://ruanmuller.com/2009/07/29/new-dos-vulnerability-affects-all-versions-of-bind-9/" title="Add 'New DoS Vulnerability Affects All Versions of BIND 9' to SlashDot"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/slashdot.png" title="Add 'New DoS Vulnerability Affects All Versions of BIND 9' to SlashDot" alt="Add 'New DoS Vulnerability Affects All Versions of BIND 9' to SlashDot" border="0" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/share.php?u=http://ruanmuller.com/2009/07/29/new-dos-vulnerability-affects-all-versions-of-bind-9/&amp;t=New+DoS+Vulnerability+Affects+All+Versions+of+BIND+9" title="Add 'New DoS Vulnerability Affects All Versions of BIND 9' to FaceBook"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/facebook.png" title="Add 'New DoS Vulnerability Affects All Versions of BIND 9' to FaceBook" alt="Add 'New DoS Vulnerability Affects All Versions of BIND 9' to FaceBook" border="0" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home?status=http://ruanmuller.com/2009/07/29/new-dos-vulnerability-affects-all-versions-of-bind-9/" title="Add 'New DoS Vulnerability Affects All Versions of BIND 9' to Twitter"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/twitter.png" title="Add 'New DoS Vulnerability Affects All Versions of BIND 9' to Twitter" alt="Add 'New DoS Vulnerability Affects All Versions of BIND 9' to Twitter" border="0" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://ruanmuller.com/2009/07/29/new-dos-vulnerability-affects-all-versions-of-bind-9/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DroneBL DDosed by DSL Modems and Routers infected by Botnet Worm</title>
		<link>http://ruanmuller.com/2009/03/23/dronebl-ddosed-by-dsl-modems-and-routers-infected-by-botnet-worm/</link>
		<comments>http://ruanmuller.com/2009/03/23/dronebl-ddosed-by-dsl-modems-and-routers-infected-by-botnet-worm/#comments</comments>
		<pubDate>Tue, 24 Mar 2009 03:06:25 +0000</pubDate>
		<dc:creator>Ruan</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[bot]]></category>
		<category><![CDATA[dd-wrt]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[DroneBL]]></category>
		<category><![CDATA[linksys]]></category>
		<category><![CDATA[router]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://ruanmuller.com/?p=252</guid>
		<description><![CDATA[&#8220;The people who bring you the DroneBL DNS Blacklist services, while investigating an ongoing DDoS incident, have discovered a botnet composed of exploited DSL modems and routers. OpenWRT/DD-WRT devices all appear to be vulnerable. What makes this worm impressive is the sophisticated nature of the bot, and the potential damage it can do not only [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>&#8220;The people who bring you the DroneBL DNS Blacklist services, while investigating an ongoing DDoS incident, have discovered a <a href="http://dronebl.org/blog/8" target="_blank">botnet composed of exploited DSL modems and routers</a>. OpenWRT/DD-WRT devices all appear to be vulnerable. What makes this worm impressive is the sophisticated nature of the bot, and the potential damage it can do not only to an unknowing end user, but to small businesses using non-commercial Internet connections, and to the unknowing public taking advantage of free Wi-Fi services. The botnet is believed to have infected 100,000 hosts.&#8221;</p></blockquote>
<p>Poorly configured devices that allow remote administration access from the WAN side, combined with weak passwords for root, appears to be the reason for the successful proliferation of the worm.</p>
<p>Via <a href="http://www.slashdot.org">Slashdot</a></p>
<div class="social_bookmark"><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://ruanmuller.com/2009/03/23/dronebl-ddosed-by-dsl-modems-and-routers-infected-by-botnet-worm/&amp;title=DroneBL+DDosed+by+DSL+Modems+and+Routers+infected+by+Botnet+Worm" title="Add 'DroneBL DDosed by DSL Modems and Routers infected by Botnet Worm' to digg"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/digg.png" title="Add 'DroneBL DDosed by DSL Modems and Routers infected by Botnet Worm' to digg" alt="Add 'DroneBL DDosed by DSL Modems and Routers infected by Botnet Worm' to digg" border="0" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?title=DroneBL+DDosed+by+DSL+Modems+and+Routers+infected+by+Botnet+Worm&amp;url=http://ruanmuller.com/2009/03/23/dronebl-ddosed-by-dsl-modems-and-routers-infected-by-botnet-worm/" title="Add 'DroneBL DDosed by DSL Modems and Routers infected by Botnet Worm' to SlashDot"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/slashdot.png" title="Add 'DroneBL DDosed by DSL Modems and Routers infected by Botnet Worm' to SlashDot" alt="Add 'DroneBL DDosed by DSL Modems and Routers infected by Botnet Worm' to SlashDot" border="0" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/share.php?u=http://ruanmuller.com/2009/03/23/dronebl-ddosed-by-dsl-modems-and-routers-infected-by-botnet-worm/&amp;t=DroneBL+DDosed+by+DSL+Modems+and+Routers+infected+by+Botnet+Worm" title="Add 'DroneBL DDosed by DSL Modems and Routers infected by Botnet Worm' to FaceBook"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/facebook.png" title="Add 'DroneBL DDosed by DSL Modems and Routers infected by Botnet Worm' to FaceBook" alt="Add 'DroneBL DDosed by DSL Modems and Routers infected by Botnet Worm' to FaceBook" border="0" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home?status=http://ruanmuller.com/2009/03/23/dronebl-ddosed-by-dsl-modems-and-routers-infected-by-botnet-worm/" title="Add 'DroneBL DDosed by DSL Modems and Routers infected by Botnet Worm' to Twitter"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/twitter.png" title="Add 'DroneBL DDosed by DSL Modems and Routers infected by Botnet Worm' to Twitter" alt="Add 'DroneBL DDosed by DSL Modems and Routers infected by Botnet Worm' to Twitter" border="0" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://ruanmuller.com/2009/03/23/dronebl-ddosed-by-dsl-modems-and-routers-infected-by-botnet-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New rogue DHCP server malware</title>
		<link>http://ruanmuller.com/2009/03/16/new-rogue-dhcp-server-malware/</link>
		<comments>http://ruanmuller.com/2009/03/16/new-rogue-dhcp-server-malware/#comments</comments>
		<pubDate>Tue, 17 Mar 2009 06:00:05 +0000</pubDate>
		<dc:creator>Ruan</dc:creator>
				<category><![CDATA[Data Centers]]></category>
		<category><![CDATA[Development]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Telecommunications]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://ruanmuller.com/?p=246</guid>
		<description><![CDATA[A bold new type of malware has been identified.  Its attack vector is based on hijacking the DNS settings for devices on a local area network. Any device regardless of operating system that depends on an internal or external name server can be affected. The trojan configures and runs a rogue DHCP daemon on the [...]]]></description>
			<content:encoded><![CDATA[<p>A bold new type of malware has been identified.  Its attack vector is based on hijacking the DNS settings for devices on a local area network. Any device regardless of operating system that depends on an internal or external name server can be affected.</p>
<p>The trojan configures and runs a rogue DHCP daemon on the infected host. Other devices on the same LAN are misled into using name servers settings provided by the trojan DHCP daemon for DNS lookups instead of using the origional configured name servers.</p>
<p>Devices on the network are then sent to fraudulent websites that can be more difficult to identify as imposters since the DNS lookups appear correct.</p>
<p>This is a more advanced attack of a well known vector of attacking a systems hosts file, but by being system agnostic and using the familiar DNS protocol, it is much more effective.</p>
<p>More details can be found at <a href="http://isc.sans.org/diary.html?storyid=6025" target="_blank">SANS</a></p>
<div class="social_bookmark"><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://ruanmuller.com/2009/03/16/new-rogue-dhcp-server-malware/&amp;title=New+rogue+DHCP+server+malware" title="Add 'New rogue DHCP server malware' to digg"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/digg.png" title="Add 'New rogue DHCP server malware' to digg" alt="Add 'New rogue DHCP server malware' to digg" border="0" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://slashdot.org/bookmark.pl?title=New+rogue+DHCP+server+malware&amp;url=http://ruanmuller.com/2009/03/16/new-rogue-dhcp-server-malware/" title="Add 'New rogue DHCP server malware' to SlashDot"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/slashdot.png" title="Add 'New rogue DHCP server malware' to SlashDot" alt="Add 'New rogue DHCP server malware' to SlashDot" border="0" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/share.php?u=http://ruanmuller.com/2009/03/16/new-rogue-dhcp-server-malware/&amp;t=New+rogue+DHCP+server+malware" title="Add 'New rogue DHCP server malware' to FaceBook"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/facebook.png" title="Add 'New rogue DHCP server malware' to FaceBook" alt="Add 'New rogue DHCP server malware' to FaceBook" border="0" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,border=0,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home?status=http://ruanmuller.com/2009/03/16/new-rogue-dhcp-server-malware/" title="Add 'New rogue DHCP server malware' to Twitter"><img src="http://ruanmuller.com/wp-content/plugins/social-bookmarking-reloaded/twitter.png" title="Add 'New rogue DHCP server malware' to Twitter" alt="Add 'New rogue DHCP server malware' to Twitter" border="0" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://ruanmuller.com/2009/03/16/new-rogue-dhcp-server-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

