pen-test
[Top] [All Lists]

Re: testing dns servers

To: Zhihao <zhihao@root.sg>
Subject: Re: testing dns servers
From: mark foster <mark@foster.cc>
Date: Sun, 15 Apr 2007 21:38:00 -0700
Cc: pen-test@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
In-reply-to: <000301c77f2a$3eafc890$bc0f59b0$@sg>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <000301c77f2a$3eafc890$bc0f59b0$@sg>
Resent-date: Mon, 16 Apr 2007 17:39:44 -0600 (MDT)
Resent-from: pen-test-return-1078483972@securityfocus.com
Resent-message-id: <20070416233944.643D414884A@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
User-agent: Thunderbird 1.5.0.10 (X11/20070306)
Zhihao wrote:
> Hi,
>
> How would you guys test a dns server for holes?
>
> Here are some that i thought of..
>
> 1. Make sure it does not allow recursive queries.
> 2. Make sure it does not allow zone transfers from unauthorized hosts.
> 3. Make sure it is not vulnerable to dns cache poisoning.
>
> Anything other vectors we could look at?
>
>   
Does it allow unsecured dynamic updates?
If so, you could add wpad as an A record to example.com and stealthily
capture web browser traffic from that domain.
http://mark.foster.cc/wiki/index.php/User:Fostermarkd/WPAD

Or update www or mail records. Obviously a huge problem.

Is the control channel secured (rndc for bind usually runs on port
tcp/953). It is supposed to be secured with a key.

There is also the possibility of dns cache snooping.
http://www.sysvalue.com/papers/DNS-Cache-Snooping/

-- 
Said one park ranger, 'There is considerable overlap between the 
 intelligence of the smartest bears and the dumbest tourists.'
Mark D. Foster, CISSP <mark@foster.cc>  http://mark.foster.cc/


------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>