<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Number of Rogue DNS Servers Increasing</title>
	<atom:link href="http://cubist.cs.washington.edu/Security/2008/02/15/number-of-rogue-dns-servers-increasing/feed/" rel="self" type="application/rss+xml" />
	<link>http://cubist.cs.washington.edu/Security/2008/02/15/number-of-rogue-dns-servers-increasing/</link>
	<description></description>
	<pubDate>Sun, 12 Oct 2008 20:01:15 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Robert</title>
		<link>http://cubist.cs.washington.edu/Security/2008/02/15/number-of-rogue-dns-servers-increasing/#comment-1081</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Sat, 16 Feb 2008 07:22:50 +0000</pubDate>
		<guid isPermaLink="false">http://cubist.cs.washington.edu/Security/2008/02/15/number-of-rogue-dns-servers-increasing/#comment-1081</guid>
		<description>There are many interesting DNS attacks that can be utilized by adversaries.  Many companies fail to realize the importance of a properly secured DNS system.  Since a lot of companies have their own DNS servers that serve their clients requests, an improperly secured system can allow an adversary to create a new root zone (.) on their DNS servers and then create nested zones like com, net, etc.  Through this they can spoof addresses for every client behind that DNS server or simply just perform a DoS on client lookups.

Adversaries can also request zone transfers from improperly secured servers and learn a lot about the internal setup of a corporate network including server names and IP addresses.

It is important for ISPs and companies to secure their DNS systems because although DNS serves a simple purpose, it can be an easy target for adversaries.  Simple solutions like secured zone transfers and split DNS configurations are easy to implement and can be very effective against stopping these kinds of attacks.</description>
		<content:encoded><![CDATA[<p>There are many interesting DNS attacks that can be utilized by adversaries.  Many companies fail to realize the importance of a properly secured DNS system.  Since a lot of companies have their own DNS servers that serve their clients requests, an improperly secured system can allow an adversary to create a new root zone (.) on their DNS servers and then create nested zones like com, net, etc.  Through this they can spoof addresses for every client behind that DNS server or simply just perform a DoS on client lookups.</p>
<p>Adversaries can also request zone transfers from improperly secured servers and learn a lot about the internal setup of a corporate network including server names and IP addresses.</p>
<p>It is important for ISPs and companies to secure their DNS systems because although DNS serves a simple purpose, it can be an easy target for adversaries.  Simple solutions like secured zone transfers and split DNS configurations are easy to implement and can be very effective against stopping these kinds of attacks.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
