博客
关于我
MDNS的漏洞报告——mdns的最大问题是允许广域网的mdns单播查询,这会暴露设备信息,或者被利用用于dns放大攻击...
阅读量:797 次
发布时间:2023-02-08

本文共 2179 字,大约阅读时间需要 7 分钟。

Vulnerability Note VU#550620

Overview

Multicast DNS (mDNS) implementations may respond to unicast queries originating from sources outside the local link network. Such responses can disclose sensitive network device information and be exploited for denial-of-service (DoS) amplification attacks.

Description

Multicast DNS is designed to allow devices on a local link network to automatically discover services and devices. However, certain mDNS implementations may incorrectly respond to unicast queries from outside the local network (e.g., the WAN). This behavior can expose device information and facilitate DoS attacks due to the larger response size compared to the query.

Impact

A response to a unicast query from outside the local link can reveal device details like model numbers and operating systems. Additionally, the larger response size can be used for DoS amplification attacks.

Solution

  • Block Inbound and Outbound mDNS on the WAN

    If your organization does not require mDNS functionality, consider blocking UDP port 5353 for both inbound and outbound traffic on your WAN. This prevents mDNS queries from entering or leaving the local network.

  • Disable mDNS Services

    Some software and devices allow disabling mDNS services. Consult your vendor for details on how to disable mDNS in your specific setup.

  • Vendor Information

    The following vendors have been identified as potentially affected:

    Vendor Status Notified Updated
    Avahi mDNS - 31 Mar 2015
    Canon 10 Feb 2015 08 Apr 2015
    HP 10 Feb 2015 20 Mar 2015
    IBM 10 Feb 2015 31 Mar 2015
    Synology 10 Feb 2015 31 Mar 2015
    Cisco 10 Feb 2015 31 Mar 2015
    Citrix 10 Feb 2015 25 Mar 2015
    D-Link 10 Feb 2015 20 Mar 2015
    F5 10 Feb 2015 31 Mar 2015
    Microsoft 10 Feb 2015 09 Mar 2015
    Ricoh 10 Feb 2015 15 May 2015
    Apple 10 Feb 2015 10 Feb 2015
    CentOS 10 Feb 2015 10 Feb 2015
    Debian 10 Feb 2015 10 Feb 2015
    Dell 10 Feb 2015 10 Feb 2015

    CVSS Metrics

    Group Score Vector
    Base 6.4 AV:N/AC:L/Au:N/C:P/I:N/A:P
    Temporal 5.2 E:POC/RL:W/RC:UR
    Environmental 3.9 CDP:ND/TD:M/CR:ND/IR:ND/AR:ND

    References

    转载地址:http://smyfk.baihongyu.com/

    你可能感兴趣的文章
    Linux--进程状态
    查看>>
    Linux——静态库
    查看>>
    Linux下安装或升级Python 2.7
    查看>>
    Linux下的系统监控与性能调优:从入门到精通
    查看>>
    Linux安装Tomcat
    查看>>
    Linux就这个范儿 第18章 这里也是鼓乐笙箫 Linux读写内存数据的三种方式
    查看>>
    Linux根文件系统详解
    查看>>
    linux系统常用监控系统状态信息命令
    查看>>
    linux系统监控与硬盘分区/格式化/文件系统管理
    查看>>
    Linux系统调用分析
    查看>>
    linux缓存nscd
    查看>>
    linux软件包的一般安装方法
    查看>>
    linux软件包:RPM包、源码包、yum在线
    查看>>
    Linux进程地址管理之mm_struct
    查看>>
    Linux部署Elasticsearch(一):下载和部署Elasticsearch
    查看>>
    Linux高阶知识:Linux 中的隐藏文件
    查看>>
    Linux(3):Linux命令-文件管理
    查看>>
    Linux(7):VIM的使用
    查看>>
    Linux:CentOS安装Docker Compose
    查看>>
    Linux:安装Redis
    查看>>