Home > Security > Vulnerabilities in DNS Server Could Allow Remote Code Execution
Vulnerabilities in DNS Server Could Allow Remote Code Execution
Posted on 19 Agustus 2011 by c0decstuff
Released MS11-058 to address two vulnerabilities in the Microsoft DNS Service. One of the two issues, CVE-2011-1966, could potentially allow an attacker who successfully exploited the vulnerability to run arbitrary code on Windows Server 2008 and Windows Server 2008 R2 DNS servers having a particular DNS configuration. We’d like to share more detail in this blog post and help you make a risk decision for your environment.
- Affected DNS configuration
- Unlikely to be exploited for code execution
- More detail about the attack vector
- Answers to common questions
Affected DNS configuration
This vulnerability affects DNS servers that allow attackers to issue lookup requests for another domain name in a way that would cause the DNS server to request the answer from a malicious DNS server. Specifically, if an attacker can cause a DNS server to request a DNS NAPTR resource record from a malicious DNS server, the attacker could potentially trigger the vulnerability described by CVE-2011-1966 on the DNS server of which the attacker is making the request.
One common affected configuration is a caching or relay DNS server on a corporate network where a malicious user is lurking. Less likely to be affected are authoritative DNS servers hosting zones exposed to the Internet, where recursion is often disabled. For example, anyone on the Internet can connect to the microsoft.com authoritative DNS server, but that server will not relay requests to a malicious DNS server.
More information about the DNS protocol, DNS recursion and forwarding:
Unlikely to be exploited for code execution
An affected system receiving a malicious NAPTR resource record from a malicious DNS server will result in heap memory corruption. For this reason, the security bulletin describes this issue as having the potential for remote code execution. However, due to the nature of this vulnerability, it is far more likely to result in a denial-of-service condition where the DNS service terminates unexpectedly and less likely to result in remote code execution.
This is due to the type of vulnerability and the platform mitigations provided by Windows Server 2008. The issue is a sign-extension vulnerability where a small negative number is expanded to a larger type without proper checks. Later, this large negative number is used as a memcpy count to populate a heap buffer. The copy length will always be at least 0x80000000 bytes long so the copy operation itself will likely fail in the absence of 2+ GB of memory available to be copied. Even if an attacker is able to successfully populate memory for the copy to succeed and massage the heap to gain control of the process, the platform mitigations of ASLR, DEP, and the heap metadata protection must still be overcome before malicious code could be run. And, finally, an attacker has only three opportunities to exploit a particular DNS server - the service control manager will no longer restart it after it crashes three times. While code execution is theoretically possible, we think a denial-of-service is most likely. Hence, we have rated the likelihood of exploit code for remote code execution appearing in the next 30 days as “3 – Functioning Exploit Code Unlikely”.
More detail about the attack vector
Due to the distributed nature of the DNS protocol, DNS servers configured to resolve names on behalf of client and applications usually support recursion (unless explicitly disabled by Admin), allowing them to talk and exchange information with other DNS Servers. The vulnerability exists in the way a Microsoft DNS Server parses NAPTR records from a remote DNS server. Here is an example, assuming the attacker controls the contoso.com DNS server and has configured it to return malicious NAPTR record data:
The victim DNS server in this case could be an unpatched Microsoft DNS Server with recursion / forwarding enabled. The attacker knows that the victim server will communicate with the contoso.com DNS Server to fetch the DNS NAPTR record requested by the client. The attacker’s malicious DNS Server then responds with the malformed NAPTR data which triggers a crash on the victim DNS Server. The victim server crashes due to the CVE-2011-1966 vulnerability while attempting to parse the malicious NAPTR record content. The crash happens only for a particular set of data for NAPTR records.
Answers to common questions
Q: I don’t host NAPTR record; is this patch applicable to my deployment?
A: Yes. As indicated above, the problem lies in the code that parses the malformed data while receiving it from other sources, not while hosting it. If your DNS Servers have recursion enabled and allows potential attackers to issue requests, this patch should be applied.
Q: I host only authoritative zones on my DNS server and have disabled recursion. Is it vulnerable?
A: This configuration is technically not vulnerable. However, due to the dynamic nature of networks, we recommend that you patch all DNS servers to prevent future configuration changes from opening attack surface.
Q: Are enterprise deployments vulnerable to this attack?
A: Enterprise networks that use a web proxy and do not allow enterprise DNS server to resolve Internet names would certainly be at reduced risk. One attack vector remaining in that case is that of an attacker with minor access rights on an enterprise network bringing up a malicious DNS server. However, they will likely face difficulty in coercing the real enterprise DNS server to direct queries to it without some level of administrative privilege.
Acknowledgements
Thanks Bruce Dang, Saaransh Bagga, Shreyas Behera, Jeremy Tinder, Nicolas Guigo, Matt Miller, and Jeff Westhead for contributing to this blog post.
- MSRC Engineering
Source:technet.com
Category Article Security
140 Responses to “c0decstuff”
Total Pageviews
Labels
- Android (1)
- Aplication (14)
- ARP (1)
- Backdoored (2)
- Browser (1)
- Cloud (1)
- Exploitation (1)
- Exploits (7)
- Facebook (2)
- forensics (3)
- Hacking (11)
- Hijacking (1)
- Honeypot (1)
- HTML5 (1)
- ios (2)
- Jailbreak (2)
- Linux (1)
- Malware (5)
- metasploit (2)
- Meterpreter (1)
- Movie (1)
- Networking (1)
- News (2)
- password attack (2)
- Penetration Test (2)
- Python (1)
- reverse engineering (1)
- Rootkits (1)
- Security (12)
- shellcode (2)
- Stuxnet/Duqu (2)
- Uncategories (1)
- Virus (1)
- Vulnerability (8)
- Web (5)
- Wifi (1)
- Windows (5)
Friendlist
Security Resources
-
-
-
This feed contains no entries
-
-
-
-
-
-
-
-
-
I was not aware about this facts and here i get it huge and great points about this concept.Web Hosting
domain name in a way that would cause the DNS server to request the answer from a malicious DNS server.
Thanks a lot for sharing.
Web hosting
I am really awed! Particularly bewildering stuff you have posted here. Awe inspiring post!!
Zenyataa shoes
Webcare360 offers anonymous offshore servers. All servers available on the site are directly connected with 100Gbps+ to our backbone
نحن متخصصون في مجال التنظيف بالبخار لثقتنا بأن شركة تنظيف بالبخار بجدة الدائمة في أن النظافة وحدها لا تكفى ويجب أن نوفر التعقيم شركة تنظيف منازل بمكة والتطهير معها لضمان مكان نظيف وصحي شركة تنظيف بجدة خالي تماماً من البكتريا والجراثيم خاصة شركة نقل عفش في وجود الأطفال فالبخار تقنية شديدة التأثير في قتل البكتريا والجراثيم لذلك نحرص على استخدامه ونوفر شركة تنظيف بالبخار بالطائف أحدث التقنيات التي تعمل بالبخار لتقديم خدمات على مستوى عالي من الدقة والإتقان وتقوم
Purchasing USA-based hosting for a site that is not legal to be run in America is not a sensible thing to do. offshore bitcoin vps can be helpful for less scrupulous businesses who wish to bypass local laws or regulations, particularly for issues like copyright law, which is also known as no DMCA hosting.
But this doesn’t mean that you can host illegal content which is strictly forbidden I.e. Phishing, Spamming. Scamming, Carding, Fraudulent activities, Child Porn and material that supports Terrorism.
comprar alargador de pene
VigRX Plus Où Acheter
Phallosan Forte
th"=ferh a<
potenzmittel frau
Member xxl
https://nuovo-inizio.com/
esteroides
machoman
BeMass Opiniones
Anabolic Rx24 Efectos
eron plus
https://nuevo-comienzo.com/
profolan
Potencialex opinion
http://penis-enlargement-pills2020.com/
Virility EX composition
http://penis-enlargement-tablets2020.com/
machoman
Erofertil effetti
Penigen Où Acheter
Atlant Gel
https://nuovo-inizio.com/dieta-chetogenica/
http://suplementos-para-masa-muscular.eu/titanodrol.html
https://nuovo-inizio.com/sono-a-dieta-ma-non-riesco-a-perdere-peso/
https://the-new-beginning.co.uk/curcuma/
http://top3-muscle-mass-supplements.com/how-to-improve-the-appearance-of-your-muscles.html
green barley plus
alimentazione per fare massa
miglior allenamento per massa
Penilux Gel opinion
programme prise de volume
http://potenzmittel-online-bestellen-de.eu/biobelt.html
cual es el mejor suplemento para ganar masa muscular
creatina para aumentar masa muscular
prendre volume bras
bodybuilding voedingssupplementen
fast burn extreme comprar
proteine per gonfiare i muscoli
http://penisverlangerung-pillen-de.eu/titan-gel.html
ganador de masa muscular
http://penisverlangerung-pillen-de.eu/bathmate.html
integratori my personal trainer
idecalica
http://bigger-penis-pills.co.uk/
http://muscle-mass-suplemetns.co.uk/
http://potency-pills-ranking.co.uk/
http://potency-pills-ranking.co.uk/erogan.html
http://best-slimming-pills-ranking.co.uk/bet-on-apple-vinegar-and-get-rid-of-the-unwanted-kilograms.html
http://penisznovelo-eljarasok-hu.eu/erogan.html
http://potenspiller2017.ovh/xtrasize-eller-member-xxl.html
http://potenspiller2017.ovh/erogan.html
http://muscle-mass-suplemetns.co.uk/steroids.html
http://potenzmittel-online-bestellen-de.eu/erozon-max.html
http://penisverlangerung-pillen-de.eu/turbomaxblue.html
http://best-slimming-pills-ranking.co.uk/ketogenic-diet.html
http://penisverlangerung-pillen-de.eu/Penilux-Gel.html
http://potenspiller2017.ovh/Potensproblem.html
http://potenzmittel-online-bestellen-de.eu/vigrxplus.html
http://potens-piller-se.eu/biobelt.html
http://odchudzanka.pl/black-latte-dzialanie-sklad-opinie-cena-i-gdzie-kupic/
http://tabletky-na-erekci-cz.eu/eronplus.html
http://jak-prodlouzit-penis-cz.eu/eroxel.html
http://penisverlangerung-pillen-de.eu/Phyton-Gel.html
http://potenspiller2017.ovh/machoman-eller-eron-plus.html
http://potenzmittel-online-bestellen-de.eu/Erofertil.html
http://ranking-powiekszanie-penisa.eu/TurboMaxBlue.html
http://ranking-powiekszanie-penisa.eu/erozonmax.html
zinc musculation
corps musclé naturellement
erofertil apotheke
fitness dieet man spiermassa
trattamento perdita capelli
que es erogan para que sirve
potentialex
penisverlängerung kaufen
como aumentar el grosor de tu pene
dr extenda tablete
member xxl pareri
soin pour maigrir
pastile de dormit naturiste
eroxel gél
nutrigo lab burner
preparaty na odchudzanie opinie
come ingrandire pene
ćwiczenia żeby szybko schudnąć z brzucha
erekcja a stres
muskel aufbau
allenamento alla produzione del testo scritto
capelli a spazzola
pilule pour se muscler sans effort
potenciadores naturales de testosterona
anabolizzanti per palestra
meber xxl
prodotti x aumentare la massa muscolare
rhodiola rosea foro
piperinox avis client
testo ultra gold
farmaci legali per aumentare la massa muscolare
integratori per microcircolo
dr.extenda
test testosteron
https://the-new-beginning.co.uk/ranking-of-slimming-pills/
https://nuevo-comienzo.com/clasificacion-de-las-pildoras-de-adelgazamiento/
regaine precio
dr erectie
contro la caduta dei capelli
http://prodottiperlacadutadeicapelli.com/annurkap.html
https://the-new-beginning.co.uk/
diet tablets
penis enlargement surgery cost uk
best slimming pills
http://fr-impuissance-traitement.eu/
keto tabletten
http://basta-testosteronboosters-se.eu
http://pour-la-masse.ovh
http://umbb-handball.fr/
http://www.swift-italia.it/
http://shirlink.com/
http://ko21.fr/erogan-dosage/
http://ko21.fr/redresser-le-penis/
http://es.detoxyn.org/
http://bkproma.it/penieno-significato/
http://bkproma.it/stimolante-pene/
http://bkproma.it/allungamento-pene-pillole/
http://pillole-per-dimagrire-che-funzionano2018.ovh
http://speed-com.fr/comment-utiliser-le-titan-gel/
http://los-mejores-boosters-de-testosterona-es.eu
http://pilloleperdimagrirevelocemente.blogspot.com
Many blogs like this cover subjects that just aren’t covered by magazines.
offshoreservers.net
Гадания на будущее для женщин онлайн позволяет увидеть, что человека подстерегает в ближайшее время. Способ понять грядущие события постоянно манил род человеческий. Всякий желает предугадать собственную судьбу и считает конкретные типы ворожбы гораздо больше действенными.
Интернет-магазин функционирует уже более шести лет, и за столь долгий срок умудрился охарактеризовать себя в качестве идеальной торговой платформы. На портале hydraruzxpnew4af onion вы можете приобрести продукты на персональный вкус и бюджет. В наши дни 99% определенных торговых договоров осуществляют в интернет-сети. Гидра РУ – это крупнейший онлайн-магазин, в котором имеется возможность приобрести какие угодно продукты по самой выгодной цене.