Cyber Security News

Unpatched DNS Bug Let Attackers to Perform DNS Poisoning Attacks

An unpatched security vulnerability was found in the domain name system (DNS) component of a popular C standard library in many well-known IoT products.

Researchers from Nozomi Networks Labs said, “The flaw was caused by the predictability of transaction IDs included in the DNS requests generated by the library, which may allow attackers to perform DNS poisoning attacks against the targeted devices”.

The flaw affects the DNS implementation of two popular C libraries called uClibc and uClibc-ng that are used for developing embedded Linux systems.

uClibc is used by major vendors such as Linksys, Netgear, and Axis, or Linux distributions such as Embedded Gentoo. It is one of the possible C standard libraries available and specifically focuses on embedded systems.

uClibc-ng is a fork particularly designed for OpenWRT, a common OS for routers possibly deployed throughout various critical infrastructure sectors.

Researchers say that a “flaw affecting a C standard library can be a bit complex since there would be hundreds or thousands of calls to the vulnerable function in multiple points of a single program and the vulnerability would affect an indefinite number of other programs from multiple vendors configured to use that library”.

Poisoning Attack

In a DNS poisoning attack, an attacker is capable to trick a DNS client into accepting a forged response, as a result inducing a certain program into performing network communications with an arbitrarily defined endpoint, and not the legitimate one.

The successful exploitation of the flaw could allow a Man-in-the-Middle attack since the attacker, by poisoning DNS records, is capable of rerouting network communications to a server under their control.

The attacker might then steal and/or manipulate information transmitted by users, and perform other attacks against those devices to completely compromise them.

Technical Analysis of the Issue

The experts from Nozomi Networks Labs noticed the trace of DNS requests performed by a connected device using the uClibc library and found some weirdness caused by an internal lookup function.

DNS lookup function of uClibc Library

Experts discovered that the DNS lookup request’s transaction ID was predictable and a DNS poisoning attack might be possible under these circumstances.

Mitigation

According to the researchers, devices from more than 200 vendors are currently at risk of DNS poisoning or DNS spoofing attack. Therefore, it is recommended to increase your network visibility and security in both IT and OT environments.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago