Short Name |
DNS:EXPLOIT:TRANSPOOF |
|---|---|
Severity |
Info |
Recommended |
No |
Recommended Action |
Drop Packet |
Category |
DNS |
Keywords |
MS08-037 KB953230 DNS |
Release Date |
2008/07/08 |
Update Number |
1213 |
Supported Platforms |
This signature detects attempts to exploit a known vulnerability in DNS servers. Attackers can spoof DNS replies by sending multiple crafted packets to DNS servers. A successful attack can result in redirected traffic to unintended locations.
Multiple vendors' implementations of the DNS protocol are prone to a DNS-spoofing vulnerability because the software fails to securely implement random values when performing DNS queries. Successfully exploiting this issue allows remote attackers to spoof DNS replies, allowing them to redirect network traffic and to launch man-in-the-middle attacks. This issue affects Microsoft Windows DNS Clients and Servers, ISC BIND 8 and 9, and multiple Cisco IOS releases; other DNS implementations may also be vulnerable.