DNSSEC, From An End-User Perspective, Part 3
Posted on 8:26 AM by Tina
In the first post of this DNSSEC series, I have shown the problem (DNS vulnerabilities), and in the second post, the "solution." In this third post, I am going to analyze DNSSEC. Can DNSSEC protect the users against all of the attacks? Or just part of them? What about corner cases?
The following list are the attack types from the first post, where DNSSEC can protect the users:
- DNS cache poisoning the DNS server, "Da Old way"
- DNS cache poisoning, "Da Kaminsky way"
- ISP hijack, for advertisement or spying purposes
- Captive portals
- Pentester hijacks DNS to test application via active man-in-the-middle
- Malicious attacker hijacks DNS via active MITM
The following list are the attack types from the first post, where DNSSEC cannot protect the users:
- Rogue DNS server set via malware
- Having access to the DNS admin panel and rewriting the IP
- ISP hijack, for advertisement or spying purposes
- Captive portals
- Pentester hijacks DNS to test application via active man-in-the-middle
- Malicious attacker hijacks DNS via active MITM
If you are a reader who thinks while reading, you might say "What the hell? Am I protected or not???". The problem is that it depends… In the case where the attacker is between you and your DNS server, the attacker can impersonate the DNS server, downgrade it to a non DNSSEC aware one, and send responses without DNSSEC information.
Now, how can I protect against all of these attacks? Answer is "simple":
- Configure your own DNSSEC aware server on your localhost, and use that as a resolver. This is pretty easy, even I was able to do it using tutorials.
- Don't let malware run on your system! ;-)
- Use at least two-factor authentication for admin access of your DNS admin panel.
- Use a registry lock (details in part 1).
- Use a DNSSEC aware OS.
- Use DNSSEC protected websites.
- There is a need for an API or something, where the client can enforce DNSSEC protected answers. In case the answer is not protected with DNSSEC, the connection can not be established.
Now some random facts, thoughts, solutions around DNSSEC:
- Did you know .SE signed its zone with DNSSEC in September 2005, as the first TLD in the world?
- Did you know DNSSEC was first deployed at the root level on July 15, 2010?
- Did you know .NL become the first TLD to pass 1 million DNSSEC-signed domain names?
- Did you know that Hungary is in the testing phase of DNSSEC (watch out, it is Hungarian)?
- Did you know that you can also use and test that cool DNSSEC validator?
- Did you know that there are alternative solutions like DNSCrypt?
- Did you know that in the future you might be able to enforce HSTS via DNSSEC?
- Did you know that in the future you might be able to use certificate pinning via DNSSEC?
Note from David:
Huh, I have just accidentally deleted this whole post from Z, but then I got it back from my browsing cache. Big up to Nir Sofer for his ChromeCacheView tool! Saved my ass from kickin'! :D
Related news
- Best Hacking Tools 2020
- Hacks And Tools
- Hacker Tools For Mac
- Hack Tools For Mac
- What Is Hacking Tools
- Hack Tools For Ubuntu
- Pentest Box Tools Download
- Hacker Tools Apk
- New Hack Tools
- How To Hack
- Hacker Tools Online
- Hack Tools Mac
- Hack Tools Pc
- Hacker Tools Linux
- Hack Tools For Ubuntu
- Hack Tools For Windows
- Pentest Tools Nmap
- Hack Apps
- Hack Website Online Tool
- Hack Tools Mac
- Hack Tools For Ubuntu
- Hack Tool Apk
- Ethical Hacker Tools
- Hack Tools For Ubuntu
- Hack Tools Github
- How To Make Hacking Tools
- Hacker Tools Software
- Hacker Tools For Mac
- Hack Tools Download
- Nsa Hacker Tools
- Hack Tools For Ubuntu
- Hack Tools For Pc
- How To Make Hacking Tools
- Hacking Tools Online
- Hack And Tools
- Hacking Tools Github
- Hacker Tools Mac
- Pentest Tools Tcp Port Scanner
- Hak5 Tools
- Hacking Tools For Beginners
- Hacker Tools Mac
- Pentest Tools Download
- Pentest Tools Apk
- Pentest Tools List
- Hacks And Tools
- Pentest Tools Bluekeep
- Hack Website Online Tool
- Hacking Apps
- Hack And Tools
- Hacker Tools For Pc
- World No 1 Hacker Software
- Tools 4 Hack
- Pentest Tools Download
- Tools Used For Hacking
- Hacking Tools For Mac
- Install Pentest Tools Ubuntu
- Tools For Hacker
- Hacking Tools For Windows 7
- Pentest Tools Bluekeep
- Pentest Tools Website Vulnerability
- Hacking Tools Windows
- Hacker Security Tools
- Hacks And Tools
- Hacking Tools For Games
- Hack Tools 2019
- Pentest Tools Framework
- Pentest Tools Tcp Port Scanner
- Pentest Tools Download
- Game Hacking
- Easy Hack Tools
- How To Hack
- What Is Hacking Tools
- Free Pentest Tools For Windows
- Hack App
- Physical Pentest Tools
- Hacking App
- Hacker Tools Hardware
- Hacker Tools Apk Download
- Pentest Box Tools Download
- Nsa Hack Tools Download
- How To Hack
- Hack Rom Tools
- Pentest Tools For Windows
- Hacking Tools For Beginners
- Hacker Tools Free
- World No 1 Hacker Software
- Tools Used For Hacking
- Hacking Tools Name
- Hacker Tools Apk
- Pentest Tools Website
- Hacking Tools Download
- Hack Rom Tools
- Hacking Tools For Windows 7
- Hack Website Online Tool
- Hacking Tools Mac
- Android Hack Tools Github
- Hack Website Online Tool
- Hack Tool Apk
- Pentest Tools For Windows
- Hacking Tools Pc
- Hack Tools For Games
- Pentest Tools Kali Linux
- Hacking App
- Hacker Tools For Ios
- Hacking Tools For Kali Linux
- Pentest Tools Github
- Nsa Hack Tools
- Blackhat Hacker Tools
- Hacking Tools Windows
- Pentest Tools Port Scanner
- Nsa Hacker Tools
- Pentest Tools Review
- Hacking Tools For Windows
- Hackrf Tools
- Free Pentest Tools For Windows
- Hack Tools Pc
- Hacker Hardware Tools
- Hackers Toolbox
- Hacker Tools Online
- Hacker Tools Mac
- Hacker Tools 2020
- Pentest Tools For Android
- Hacker Tools
- Hacking Tools Software
- Hacker Tools Linux
- Hacker Tools Apk
- Hacker Tools List
- Pentest Tools Subdomain
- Top Pentest Tools
- Hacker
- Hacker Tools Windows
- Pentest Tools Android
- Hacking Tools Name
- Nsa Hack Tools
- Hacking Tools Mac
- Pentest Tools Framework
- Pentest Tools Apk
- Hacker Tools List
- Nsa Hack Tools Download
- Hacking Tools For Games
- Hacker Tools List
- Hacker Tools Free Download
- Hacker Tools Free
- Hacker Tools For Windows
- Hack Tools 2019
- Hacking Tools For Games
- Hack Tools For Windows
0 comments:
Post a Comment