DNS_EXPLOIT named overflow attempt

 

Code: p426

Severity: Warning

 

Description: This event is generated by an attempted buffer overflow associated with incorrect validation of NXT records.

Impact: Severe. The DNS server can be compromised allowing the attacker access with the privileges of the user running BIND. This attack is sometimes referred to as ADMROCKS because a subdirectory named ADMROCKS is placed in the directory associated with BIND software.

Corrective: Upgrade to a version of BIND 8.2.2, or greater or patch vulnerable versions of BIND.