Re: [MaraDNS list] DNS under exploited attack?

david sevilla <[email protected]> Wed, 16 Nov 2011 06:56:23 -0700
Newsgroups gmane.network.dns.maradns.general
Message-ID <[email protected]>
I wonder if Anon or/and lulzsec are involved :P

> Date: Wed, 16 Nov 2011 13:19:12 +0100
> To: [email protected]
> From: [email protected]
> CC: [email protected]
> Subject: [MaraDNS list] DNS under exploited attack?
> 
> FYI - in case this would be a new form of DoS.
> -----
> 
> From: Barry Greene <[email protected]>
> Subject: Update: BIND 9 recursive error being investigated
> To: undisclosed-recipients:;
> 
> Interm Security Advisory: 
> http://www.isc.org/software/bind/advisories/cve-2011-tbd (CVE will be updated)
> 
> Organizations across the Internet are reporting crashes interrupting 
> service on BIND 9 nameservers performing recursive queries. Affected
> servers crash after logging an error in query.c with the following 
> message: "INSIST(! dns_rdataset_isassociated(sigrdataset))"
> 
> Multiple versions are reported as being affected, including all 
> currently supported release versions of ISC BIND 9.
> 
> ISC is actively investigating the root cause and working to produce 
> patches which avoid the crash. Further information will be made
> available soon (see the advisory 
> http://www.isc.org/software/bind/advisories/cve-2011-tbd).
> 
> It is unknown at this time if this is an exploited attack. This is 
> under investigation.
> 
> Questions, observations, and data is welcomed. Please send to 
> [email protected].
> 
> ----
> 
> jfc
>