https://www.americancityandcounty.com/wp-content/themes/acc_child/assets/images/logo/footer-logo.png
  • Home
  • Co-op Solutions
  • Commentaries
  • News
  • In-Depth
  • Multimedia
    • Back
    • Podcast
  • Resources
    • Back
    • Resources
    • Webinars
    • White Papers
    • Events
    • How to Contribute
    • Municipal Cost Index – Archive
    • Equipment Watch Page
    • American City & County Awards
  • Magazine
    • Back
    • Digital Editions
    • Reprints & Reuse
    • Advertise
  • About Us
    • Back
    • About Us
    • Contact Us
    • Privacy Statement
    • Terms of Service
American City and County
  • NEWSLETTER
  • Home
  • Co-op Solutions
  • Commentaries
  • News
  • In-Depth
  • Multimedia
    • Back
    • Podcasts
  • Resources
    • Back
    • Webinars
    • White Papers
    • Events
    • How to Contribute
    • American City & County Awards
    • Municipal Cost Index
    • Equipment Watch Page
  • Magazine
    • Back
    • Digital Editions
    • Reprints & Reuse
    • Subscribe to GovPro
    • Manage GovPro Subscription
    • Advertise
  • About Us
    • Back
    • About Us
    • Contact Us
    • Cookie Policy
    • Privacy Stament
    • Terms of Service
  • newsletter
  • Administration
  • Economy & Finance
  • Procurement
  • Public Safety
  • Public Works & Utilities
  • Smart Cities & Technology
acc.com

Public Safety


What’s The Cache?

What’s The Cache?

Domain Name System (DNS) cache poisoning attacks are becoming more common. The attacks involve manipulating the Internet's directory service to mimic
  • Written by American City & County Administrator
  • 1st February 2006

Domain Name System (DNS) cache poisoning attacks are becoming more common. The attacks involve manipulating the Internet’s directory service to mimic sites and trick users into conducting financial transactions or installing adware and other unwanted programs. They are becoming an increasingly common problem for the large number of outdated or poorly implemented DNS servers that are still in use today. Certain Symantec gateway security appliances, among other commonly used devices, have also become victims of DNS cache poisoning in recent months, and there is no indication that the problem will let up any time soon.Hackers use a DNS server, which they control, to send fake addresses to other DNS servers to perform malicious attacks.

“Government workers could be directed to the wrong Web site where they could be tricked into giving up personal information or worse, have their money taken,” says Michael Hyatt, president and CEO of BlueCat Networks, Richmond Hill, Ont., Canada. “The government is as vulnerable as anybody.“

As a result of these attacks, Web surfers can unknowingly become re-directed to the poisoned DNS server simply by entering the URL of a well-known, commonly used Web site. Given the power of DNS cache poisoning, many believe it will ultimately become a powerful tool for online identity theft.

BlueCat Networks manufactures DNS and Dynamic Host Configuration Protocol appliances for the conveniently centralized administration and enterprise-wide management of IP addresses, configurations and hostnames. Clients include the U.S. federal government, military and state governments of Utah, Arizona Department of Housing, Regional Transportation of Nevada and Minnesota Department of Health.

Here are some steps suggested by BlueCat networks that organizations can take to minimize the risk of cache poisoning:

  • Ensure that DNS servers are running the latest version of DNS software: BIND 9.2.x or MS Windows 2003.

  • Limit recursion to internal DNS servers. Ensure that DNS servers are not fully open to recursive queries (especially externally facing name servers).

  • Use forwarders if possible. Have internal name servers forward all non-authoritative queries to a set of forwarders and ensure that the forwarders are upgraded (latest version of DNS software) and locked down.

  • If possible, split external authoritative name servers and forwarders. External authoritative name servers need to accept queries from almost any address, but forwarders do not (they should be configured to accept queries from internal addresses only).

  • Make use of firewall services both at the network perimeter and on the DNS servers themselves.

  • Make use of TSIG (Transaction Signatures) to digitally “sign” zone transfers and zone updates.

  • Hide the version of BIND being run on the servers (do not advertise too much information).

  • Run separate nameservers (for redundancy) on “different” networks (best if different physical locations are possible).

  • Remove any unnecessary services running on the DNS servers (FTP, telnet, HTTP, etc).

  • If possible, use dedicated appliances in place of multi-purpose servers.

Tags: Public Safety

Related


  • D.C. police begin identifying Capitol rioters
    Washington, D.C.’s Metropolitan Police Department (MPD) is working with the Federal Bureau of Investigation (FBI) to identify the supporters of President Donald Trump who stormed the U.S. Capitol on Jan. 6. “MPD seeks assistance in identifying persons of interest responsible for Unlawful Entry offenses that occurred yesterday on US Capitol Grounds, 100 block of 1st […]
  • Lessons from the pandemic: Emergency sourcing of lifesaving equipment
    Being able to conceive and implement new procurement models in times of crisis requires resourcefulness, tenacity and teamwork.
  • Probabilistic genotyping in forensic DNA analysis
    Despite some criticisms, the use of PG software is an advancement that substantially improves DNA analysis
  • Hamilton County elects first female, openly gay sheriff
    After claiming to have been fired in 2017 partly for being openly gay, a former Hamilton County (Ohio) major has since defeated her supervisor to become the county’s first female and openly gay sheriff. Charmaine McGuffey, 62, had an award-winning, 33-year career, in which she became the first female major in the Hamilton County Sheriff’s […]

Leave a comment Cancel reply

-or-

Log in with your American City and County account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Colorado county’s value-based health care strategy produces savings
  • Navigating hurricane season and COVID-19 through communication
  • Florida county announces successful test of Motorola Solutions’ cloud-based P25 core technology
  • In challenging year, working with public safety to move FirstNet forward

White papers


How a unified HR system helps one public safety organization manage crews, payroll, and more in a single platform

7th January 2021

Your Roadmap to COVID-19 Funding

18th December 2020

The One Where Everyone Wins: A Mutually Beneficial Contracting Method

10th December 2020
view all

Events


PODCAST


Young Leaders Episode 4 – Cyril Jefferson – City Councilman, High Point, North Carolina

13th October 2020

Young Leaders Episode 3 – Shannon Hardin – City Council President, Columbus, Ohio

27th July 2020

Young Leaders Episode 2 – Christian Williams – Development Services Planner, Goodyear, Ariz.

1st July 2020
view all

Twitter


AmerCityCounty

The latest episode The Young Leaders Podcast focuses on Cyril Jefferson. Cyril is the youngest African American to… twitter.com/i/web/status/1…

27th October 2020
AmerCityCounty

Hillsboro, Oregon is pioneering a new #renewableenergy generation technology through a partnership with… twitter.com/i/web/status/1…

27th October 2020
AmerCityCounty

The impact of the #COVID19 pandemic on #telework was swift and profound. Now, the big question is whether – and to… twitter.com/i/web/status/1…

26th October 2020
AmerCityCounty

Get ready for the can't-miss webinar on how to kickstart your efficiency improvement plan with Luke Anderson of… twitter.com/i/web/status/1…

26th October 2020
AmerCityCounty

Among all states headed into the 2020 general election, which ones have voting populations that are the most demogr… twitter.com/i/web/status/1…

26th October 2020
AmerCityCounty

We want to hear from you! Share your thoughts in our readership survey to help us shape future content so that we c… twitter.com/i/web/status/1…

23rd October 2020
AmerCityCounty

See how cities different approaches to distribute masks in their communities >> spr.ly/6010GAPLa

23rd October 2020
AmerCityCounty

While #facialrecognition is a powerful tool that can improve law enforcement efficiency, that doesn’t necessarily t… twitter.com/i/web/status/1…

23rd October 2020

Newsletters

Sign up for American City & County’s newsletters to receive regular news and information updates about local governments.

Resale Insights Dashboard

The Resale Insights Dashboard provides model-level data for the entire used equipment market to help you save time and money.

Municipal Cost Index

Updated monthly since 1978, our exclusive Municipal Cost Index shows the effects of inflation on the cost of providing municipal services

Media Kit and Advertising

Want to reach our digital audience? Learn more here.

DISCOVER MORE FROM INFORMA TECH

  • IWCE’s Urgent Communications
  • IWCE Expo

WORKING WITH US

  • About Us
  • Contact Us

FOLLOW American City and County ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookies Policy
  • Terms
Copyright © 2021 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X