• Home
  • About Us
  • Contact
  • Advertise
  • Awards
  • Privacy Policy
  • Twitter
  • Facebook
  • RSS
TheDomains.com

ICANN on DNS Flaws

August 7, 2008 by Michael Berkens

The Internet Corporation for Assigned Names and Numbers (ICANN) announced in a press release today that it is raising awareness of a recently discovered vulnerability in the domain name system (DNS).

ICANN also released an FAQ and an online tool for domain operators to test their domains.

According to ICANN no one organization can implement a fix for this vulnerability. It requires the cooperation of all name server operators and DNS software vendors.

However, ICANN sees an important goal in spreading awareness of the need to update Internet infrastructure to cope with the threat.

Security researcher Dan Kaminsky recently discovered a design flaw in the fundamental DNS protocol. While it is not possible to fully fix this flaw, there are ways to improve resistance to it. This involves system administrators patching or reconfiguring their DNS servers.

The vulnerability affects what are called “recursive” name servers, typically installed at ISPs and corporate network gateways to assist DNS lookups and cache results for faster lookups, rather than the type of name servers used by domain registries which are “authoritative” name servers.

However, name servers can be configured to perform both “recursive” and “authoritative” functions from the same machine, and by doing so the susceptible recursive function can cause security risks for the authoritative function.

For operators of domain names, this vulnerability can be used to affect the contents of their zone if their authorities also provide recursive name service.

To detect whether a particular zone is vulnerable, ICANN has produced a tool that can check a particular domain: http://recursive.iana.org/

Domain operators should look to ensuring that all of the authoritative name servers for their domain are separated from any recursive name servers to avoid being impacted by cache poisoning attacks.

Filed Under: ICANN

About Michael Berkens

Michael Berkens, Esq. is the founder and Editor-in-Chief of TheDomains.com. Michael is also the co-founder of Worldwide Media Inc. which sold around 70K domain to Godaddy.com in December 2015 and now owns around 8K domain names . Michael was also one of the 5 Judges selected for the the Verisign 30th Anniversary .Com contest.

« Let’s Talk About Sex
As .ME Breaks the 40K Range: Now The Auction is Just Getting Silly »

Comments

  1. Kelly Lieberman says

    August 7, 2008 at 11:00 pm

    FYI:
    Moniker has posted Affiliate Summit Domain Auction list.

  2. Damir says

    August 7, 2008 at 11:01 pm

    What a tool http://recursive.iana.org

    Check it out

  3. MHB says

    August 7, 2008 at 11:09 pm

    Kelly

    Thanks but the list is like 8700 domains long.

    Its not a list of selected domains its looks like all the submitted names.

    There is no live auction only a silent one and I for one i’m not going through 8700 to find one good one.


Recent Articles

  • Dynadot increasing auction deposits
  • Rick Schwartz AiReviews.com deal sets off a flurry of AiReview related domain registrations
  • Sedo weekly domain name sales led by Diffs.com

Recent Comments

  • Raymond Hackney on Rick Schwartz weighs in on the second Coinbook.com auction
  • James K. on Rick Schwartz weighs in on the second Coinbook.com auction
  • Jose on Rick Schwartz weighs in on the second Coinbook.com auction
  • Rick Schwartz on James Booth is a bit miffed by those shitting on the .ai extension
  • brad on James Booth is a bit miffed by those shitting on the .ai extension

Categories

Archives

Copyright ©2025 TheDomains.com