Slashdot Log In
Identity Theft Hits the Root Name Servers
Posted by
CmdrTaco
on Monday May 19, @10:00AM
from the i-don't-think-i-am-who-you-think-i-am dept.
from the i-don't-think-i-am-who-you-think-i-am dept.
aos101 writes "The Renesys blog has an interesting story about networks advertising the old address space of the L root name server after ICANN changed the IP address last November. These networks were also running root name servers on the old IP address of the L root name server up until last week, so any DNS servers still using the old IP address might have been getting their answers from these bogus name servers. A very cursory examination by Renesys of one of these bogus servers found that it appeared to be providing correct responses, which might be why no one noticed the problem. As Renesys points out, the volume of traffic to a root server is staggering, so the people running these bogus root servers must have had a reason. What did they get out of it?"
Related Stories
[+]
Technology: What Could You Do With a Bogus Root Name Server? 60 comments
Barlaam notes a post from the Renesys Blog which follows up on news they discussed a couple weeks ago about the 'identity theft' of a root name server. To emphasize the issue of safeguarding such a system, they've now posted an explanation of exactly how the situation could be exploited.
"It shouldn't be too hard to see that you could end up answering every DNS query from an organization that came to you for an updated list of root name servers. Every one. And you might end up doing this for a very long time, especially if your answers were largely correct. An attack like this would have no resemblance to the YouTube hijack, where the entire planet gets a blank page and it's immediately apparent that something isn't right. Obvious events like this will continue to occur, and we'll continue to resolve them relatively quickly. But as this incident demonstrates, DNS hijacks are far less obvious and potentially far more harmful."
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.

Good Samaritans? (Score:3, Insightful)
Reply to This
Re:Good Samaritans? (Score:4, Insightful)
Reply to This
Parent
Re: (Score:3, Insightful)
Re: (Score:3, Insightful)
And, for that matter, if Bill Manning authorized the use of the address space, then it's not even an attack!
Re:Good Samaritans? (Score:5, Insightful)
The fact that those who did this had huge resources do not make it less scary, neither does the fact that nobody detected anything. Remeber how that guy operated a tor exit node to get a whole lot of interesting datas; the idea here is the same.
(A concrete example would be to send your wikipedia request to a bogus wikipedia website. It would forward all your queries to the real wikipedia, so you couldn't tell the difference (man in the middle), but on some pages it would serve you an altered page; it could also make you feel like you wrote an article, but the article would actually only show up on your copy of the bogus website, not the real one. Encryption twarts this, otherwise it's really the worst case scenario.)
And apparently, there is nothing to prevent it from happening again. Since people seem so little concerend, I must have missed some detail which makes everything fine; or at least I really hope so.
Reply to This
Parent
Re:Good Samaritans? (Score:5, Interesting)
Later, my new boss wanted to switch to a Linux based system, instead of the windows system which I'd already repurposed. I quoted him a modest server, set it up as a secure proxy for some of our internal web applications, and let the original linux system keep chugging along.
I figure I can get at least two more servers out of this, before I actually have to upgrade the system.
Maybe the guys at root-servers just left some hardware running at the old address?
They should never have relinquished the address so damn quickly. Turn off the equipment for a few weeks first and let people see that that address no longer works...Don't just let someone move in seamlessly and hijack your junk.
Reply to This
Parent
Re:Good Samaritans? (Score:5, Insightful)
Reply to This
Parent
Re:Good Samaritans? (Score:5, Insightful)
Reply to This
Parent
Re:Good Samaritans? (Score:5, Interesting)
Reply to This
Parent
Re:Good Samaritans? (Score:5, Insightful)
Most people don't pay much attention to their DNS infrastructure. The stuff doesn't need much maintenance. If it breaks, they'll notice that something is wrong, but if it continues working seamlessly, they'll ignore it.
Reply to This
Parent
Re:Good Samaritans? (Score:5, Informative)
http://blog.icann.org/?p=227 [icann.org]
It is expected that the old address will continue to work for at least six months after the transition, but will ultimately be retired from service.
1st November 2007 -> 1st May 2008 is 6 months. So they left it a few days over 6 months
Tim.
Reply to This
Parent
Re: (Score:3, Informative)
Re:Good Samaritans? (Score:4, Insightful)
For the owner of the original IP address now being vacated by ICANN, there is also maybe a self-interest motive of identifying the servers who hadn't updated so as to notify them and kill the unwanted traffic.
Given how visible this is, it's hard to imagine anyone doing it for criminal purposes and thinking they could get away with it.
Reply to This
Parent
statistics? profiling? (Score:3, Insightful)
that data would be worth something to ad men surely...
Reply to This
Re:statistics? profiling? (Score:5, Funny)
(flem, 'a', 'n'...)
Reply to This
Parent
What? (Score:5, Insightful)
How do we go from this to a headline reading Identity Theft Hits the Root Servers?
There is no reason to believe that it was malicious at all. We all are familiar with that black hat turned grey or white that wants to help out by demonstrating vulnerabilities in the system. That is just as plausible as anything else. Maybe it's the free-masons!! The Illumanati, maybe!!! The only certain thing about this is the need to secure name service. We should be glad even though it was compromised, there is no apparent damage done.
Reply to This
Harvesting NXDOMAIN hits (Score:5, Interesting)
Reply to This
Re:Harvesting NXDOMAIN hits (Score:5, Informative)
On the other hand, the person in control of the root could give bogus records for the name servers for something like com. This is unlikely to be a major problems since the TTL on all the records served by the root is 120 days. Most people are going to be querying a caching name server of some sort, so it's statistically unlikely to affect much of the population before it is detected and dealt with.
Not to plug my own work too much, but as a part of my research, I work with a team that monitors DNSSEC deployment. This is something we would in theory be able to see from our distributed polling framework, and our datasets going back to 2005 don't show anything like a rogue TLD server being published. Kind of unfortunate in a way, being that DNS isn't exactly the most interesting research topic at face value.
Reply to This
Parent
Could be several reasons (Score:5, Interesting)
A few reasons spring immediately to mind.
1. Preliminary move with the intent of actual subversion of results at a later date. This gives you an idea of what the traffic looks like, the volume you're going to have to manage, and the technical requirements of managing the subversion on top of recording important information about the systems you just subverted for later exploitation, plus any statistical information you need/want to improve your subversion process.
2. Preliminary move by a government, corporate entity, or some grouping with the intent of either wresting control of some portion of the DNS infrastructure from ICANN, or setting up a country-specific DNS infrastructure that is legally mandated. Again, you get valuable information about the kind of stuff you need to be dealing with, depending on exactly what you have in mind.
3. Same as above, but more of an idealistic style intervention, fearing malicious intent from the US government which still controls the DNS system, and trying to prepare for a time when an ICANN-free DNS system may need to be put in place.
Depending on where this stuff is actually going (and if it's the actual owner of the IP space that is doing this) of course...
Reply to This
This is the perfect Man In The Middle attack (Score:5, Insightful)
If only 5% of DNS servers hadn't updated their root servers list, and this server is listed as 1 of the 13 root servers, then these people will have .38% of the entire internet's DNS requests coming through them.
With "control" of a root server (or at least what a DNS client believed was a root server. They would be free to insert whatever records for anything they want. Think banking, finance, email, etc.
So really, the title of this article should have been if you were in organized crime, what would you do if you could transparent MITM (man in the middle) attack .38% of all web traffic on the internet.
My guess is all your accounts belong to us.....
Reply to This
Make sure you are up to date! (Score:4, Informative)
ftp://ftp.internic.net/domain/named.cache [internic.net]
Slashdot's junk filter won't allow a cut and paste of the file's contents into a post.
Reply to This
Re:Extremely vague article (Score:5, Informative)
icann hosted L-root on ip addresses they didn't have an exclusive right to use.
they decided to stop doing that and moved L-root to somewhere else.
shortly thereafter someone else decided to operate a name server on the very same IP addresses.
that's *what* happened. perhaps you meant to say that the article doesn't say *why* it happened. that would be a fair criticism.
Reply to This
Parent
Re:Extremely vague article (Score:4, Interesting)
you're missing something here. It wasn't just that "someone" else decided to operate a bogus L root server on that IP address, it's that several someones were doing this. The article states there were FOUR of these running on the OLD ip address. so you had the newly IP'd correct L server, and 4 bogus L servers (one of which was being run by ICANN itself), all using the same old IP address.
How could this happen you ask? because 3 entities not authorized to announce they host that IP block did so anyway, so there were 4 different routes to that IP block on the Internet, resulting in 4 possible places you could end up at when sending DNS queries to the old address, 198.32.64.12.
So basically there are 2 concerns here, one is that a couple of Internet entities were advertising routes for an IP block they were not authorized to advertise, and that they were running a bogus L root server from that IP block on it's old address. Bill Manning owned the IP block so his ISP was authorized to advertise that route, and it might be obvious why ICANN was also advertising a route for it as well (to try to get that traffic going to the old IP address for root lookups), but why were Community DNS and Diyixian.com advertising that route and running a bogus L root server?
Reply to This
Parent
Re:What they got (Score:5, Insightful)
Reply to This
Parent
Re: (Score:3, Informative)
they may be gathering data from NX hits, though. who could say. well, comm