bloxHub

www.infoblox.com/community

A Lesson from Nate and DNS Changer

I remember years ago, Infoblox hired our first real IT guy (my friend Nate Campi).  Not long afterward, Nate tightened up our firewall rules--et voila, I could no longer query name servers on the Internet directly.  I bristled at this, and asked Nate his rationale for cutting off our access.  We couldn't run dig and nslookup from our clients anymore!  Well, Nate felt that it was more important that we allow only internal name servers that were authorized to query name servers on the Internet (i.e., forwarders) to send DNS queries through the firewall.  As consolation, he offered me a login on one of the Linux boxen on our DMZ.

Fast forward a few years, and we see the wisdom of Nate's policy.  The DNS Changer malware infected millions of Windows computers around the Internet, changing their DNS resolver settings to point to recursive name servers that would then redirect all queriers to open proxy servers, where their traffic could be recorded and examined.  Nate's firewall rules would have countered DNS Changer:  the worst an infected computer would have experienced would have been a denial of DNS service, not the substantially more damaging divulging of data to some nefarious organization.

So take a lesson from Nate, as I should have, and tighten up your firewall rules so that only your internal name servers--and only those that resolve Internet domain names directly--can send DNS queries through your firewall to the Internet.

File attachments: 
Archived: 
Select a category: 
Section: 

Tags:

Trinzic DDI , DNS, resolver, malware, security, DNS security

Add comment

Log in or register to post comments

Welcome to bloxHub

Welcome to bloxHub, our community for users of Infoblox products. Most of our content can be viewed as a guest, but if you wish to contribute or join a conversation, you will need to log in. If you don't have a bloxHub account, we invite you to register an account and join us.

Follow us on Twitter

Follow us on Twitter at @bloxHub and we'll keep you notified of new content on the community as well as webinars and other items of interest to Infoblox users.