ITHELPSUPPORT
HOME
  • Downloads
  • Linux News
  • Windows
  • Mac
  • Website
  • Tech News
  • Reviews
  • AI
No Result
View All Result
  • Downloads
  • Linux News
  • Windows
  • Mac
  • Website
  • Tech News
  • Reviews
  • AI
No Result
View All Result
ITHelpSupport
No Result
View All Result
Home Tech News

Microsoft issues mitigation for the NXNSAttack DNS DDoS attack

by admin
June 15, 2021
125
0
168
SHARES
524
VIEWS
Share on FacebookShare on Whatsapp

Microsoft has issued a security advisory to mitigate the NXNSAttack vulnerability in DNS servers that can be used to escalate a single DNS request in a DDoS attack against authoritative DNS servers.

In a new paper, researchers from Tel Aviv University and The Interdisciplinary Center have uncovered a new vulnerability called NXNSAttack that “could be used to mount a destructive attack against both recursive resolvers and authoritative servers.” ”

In a nutshell, NXNSAttack works by an attacker sending a DNS request to a recursive server for a domain under the attacker’s control. Since this recursive server does not have authority to resolve the request, it sends a query to the authoritative DNS server for the attacker’s domain.

The authoritative server is also under the attacker’s control and will respond with a list of servers that the original resolver should query. However, this list of servers will be the target of a DNS DDoS attack, which will now be queried.

If multiple requests are made in this way, it could allow an attacker to DDoS attack an authoritative DNS server and render it unresponsive.

The attack is illustrated by the image below created by Nic.cz in its blog post regarding the NXNSAttack attack.

According to the researchers, this attack has “an amplification factor of more than 1620x the number of packets changed by the recursive resolver,” which could be disastrous for their targets.

To address this vulnerability, DNS server developers have started issuing advisories and patches for their software. Below is a list of currently known advices.

  • DNS Server Published Advisory Advisory
  • ISC BIND Security Advisor CVE-2020-8616
  • NLnet Labs Unbound CVE-2020-12662
  • NIC.CZ Not Resolver Blog Post CVE-2020-12667
  • PowerDNS Security Advice
  • Microsoft ADV200009 | Windows DNS Server Denial of Service Vulnerability
Read:  Exploring the D E A R Lottery of Nagaland State

More information about NXNSAttack can be found at the NXNSAttack.com site created by the researchers, and Nic.cz’s blog post is a recommended read.

 

Mitigating the NXNSAttack Attack on Windows DNS Servers
Microsoft’ ADV200009 | . NXNSAttack released the Windows DNS Server Denial of Service vulnerability yesterday with ‘DNS Attack Mitigation’ security advisory.

“An attacker who successfully exploited this vulnerability could cause the DNS Server service to become unresponsive.”

“To exploit this vulnerability an attacker would need to have access to at least one client and a domain that responds with a large amount of referral records without glue records pointing to the external victim subdomain. When resolving the name, for each referral record found, the resolver contacts the victim domain. This action can generate a large number of communications between the recursive resolver and the victim’s authoritative DNS server, leading to a distributed denial of service. (DDoS) attack,” explains Microsoft’s ADV200009 Security Advisor.

To mitigate this attack, Microsoft recommends that administrators use the Set-DnsServerResponseRateLimiting PowerShell cmdlet to enable response rate limiting.

Response rate limiting is a configuration option used by DNS servers to prevent them from being used in DDoS attacks using DNS amplification.

When enabled, this setting will limit the number of responses or errors that a DNS server can send to a DNS client in one second.

To check your current response rate limiting setting, you can run the Get-DnsServerResponseRateLimiting PowerShell command.

 

As you can see from the above default settings, the Windows DNS server will only respond to a client five times within one second.

If you want to increase or decrease this amount, you can do so with the Set-DnsServerResponseRateLimiting PowerShell command.

Read:  How to Deactivate Truecaller Account: A Step-by-Step Guide

For example, to reduce the number of responses to two per second, you would issue the following command:

Set-DnsServerResponseRateLimiting -ResponsesPerSec 2

 

A similar command can be used to reduce the number of errors to two per second:

Set-DnsServerResponseRateLimiting -ErrorsPerSec 2

It should be noted that utilizing the Response Rate Limiting feature will prevent a Windows DNS server from being used in a DNS amplification attack against another client. It will not, though, protect the server itself from being impacted.

Unfortunately, Microsoft has not specified what the recommended values are to mitigate this attack.

 

Get real time update about this post categories directly on your device, subscribe now.

Unsubscribe
Previous Post

European Supercomputers Hacked

Next Post

Moto G8 Energy Lite finances smartphone introduced in unmarried variant with 64GB garage

admin

admin

Related Posts

Best Gaming Laptops Under $1500 for 2025
Laptop

Best Gaming Laptops Under $1500 for 2025

by Raju Gujar
February 14, 2025
0

Gaming laptops have come a long way in recent years, offering desktop-level performance in a portable form factor. With advancements...

Read moreDetails
A side-by-side comparison image of the Samsung Galaxy S25 Ultra and the Apple iPhone 16 Pro Max. The image should highlight the front and back views

Samsung Galaxy S25 Ultra vs iPhone 16 Pro Max: Which Should You Buy in 2025?

February 13, 2025
iPhone 16 Pro-2024

iPhone 16 Pro Quick Review: A Camera Upgrade Worth Noticing

September 20, 2024

Meet the Sony WH-1000XM6 Headphones

September 19, 2024
Load More
Next Post
Moto G8 Energy Lite finances smartphone introduced in unmarried variant with 64GB garage

Moto G8 Energy Lite finances smartphone introduced in unmarried variant with 64GB garage

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

  • Deepnude App

    Deepnude App | Cloth Remover App

    950 shares
    Share 380 Tweet 237
  • Free AI Clothes Remover Websites

    493 shares
    Share 189 Tweet 118
  • iPhone 15 Pro | Pro Max Tips and Tricks

    412 shares
    Share 138 Tweet 87
  • Nokia Edge 2022 Price And Release Date 2023

    305 shares
    Share 122 Tweet 76
  • Nokia 7610 5G Review: Pros and Cons 2023

    298 shares
    Share 119 Tweet 75

© 2018-2023 ITHelpSupport.com

ITHelpSupport.com

  • Privacy-Policy
  • Terms & Conditions
  • Contact Us
  • About Us

Follow Us

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Windows
  • Linux News
  • Mac News
  • Website
  • Downloads
  • Tech News
  • AI
  • Review
    • Mobile Phone
    • Gadget
    • Apps
    • Laptop
    • Watch

© 2018-2023 ITHelpSupport.com

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.