Ads by TechWords

See your link here
Receive the latest technology news and information.
Networking
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

DNS patches cause problems, developers admit

ISC to repatch BIND over performance issues; Microsoft spells out multiple Windows bugs in its July 8 update

July 29, 2008 12:00 PM ET

Active Comments
Matt P. says: I disagree with fanboy-ish comment you responded to, but your contention is equally silly. OS X's DNS service, on both...
Anonymous says: The MS KB article for their DNS patch does not list Vista as being affected by the problem....


Computerworld - Patches released earlier this month to quash a critical bug in the Domain Name System (DNS) have slowed servers running BIND, the Internet's most popular DNS software, and crippled some systems using Windows Server.

Paul Vixie, who heads the Internet Systems Consortium (ISC), the group responsible for the BIND (Berkeley Internet Name Domain) software, acknowledged that there were problems with the July 8 fix that was rolled out as part of a multivendor update meant to patch a cache poisoning flaw discovered months before by researcher Dan Kaminsky.

"During the development cycle, we became aware of a potential performance issue on high-traffic recursive servers, defined as those seeing a query volume of greater than 10,000/queries per second," said Vixie in a message posted Monday afternoon to a BIND mailing list. "Given the limited time frame and associated risks, we chose to finish the patches ASAP and accelerate our work on the next point releases that would address the high-volume server performance concerns.

"Our immediate goal was to make patches publicly available as soon as possible," Vixie explained.

Vixie wasn't specific about the extent of the performance problems facing high-volume DNS servers, but he said that a second round of patches, due later this week, will remedy port allocation issues and "allow TCP queries and zone transfers while issuing as many outstanding UDP queries as possible."

Versions of the second update, which will be designated P2 when they're unveiled, are currently available in beta form for BIND 9.4.3 and BIND 9.5.1.

However, Vixie stressed that administrators shouldn't roll back the July 8 patched editions even if their servers are running slowly. "Until the release of the -P2 code, it is imperative that you run a -P1 version of BIND on your caching resolvers," he said. "The vulnerability is of more concern than a slow server."

The flaw Kaminsky uncovered in February makes it much easier than originally thought to insert bogus information into the Internet's routing infrastructure. A successful attack would let criminals silently redirect requests for a legitimate site to a bogus one set up to skim personal information, such as passwords to online banking accounts, from duped users.

Earlier this month, when Kaminsky announced that the vulnerability had been patched by several vendors, including ISC, Microsoft Corp. and Cisco Systems Inc., he applauded their quick cooperation. "I want to get a lot of credit to the vendors here," he added in an interview last week. "The vendors were everything that the security community ever could have asked for," he said, referring to the resources they allocated to the problem and the speed with which they cranked out patches.

Patching the DNS flaw became more important last week after hackers took exploit code public.

ISC wasn't the only vendor involved in first-round DNS patching that has issued a mea culpa. Two weeks ago, Microsoft confirmed that its July 8 DNS update, tagged as MS08-037, was crippling machines running Windows Small Business Server, a suite based on, among other programs, Windows Server 2003.

"Some customers have reported seeing random problems with services after installing MS08-037," reported several Microsoft engineers in a post to the Small Business Server (SBS) blog on July 17.

One SBS component that might fail to start, said Microsoft, was the IPSEC service, which would knock the server off the network.

Last Friday, the company unveiled a pair of support documents that spelled out the patch's unintended side effects, but also added Exchange Server 2003 and Internet Security and Acceleration (ISA) Server to the affected list.

A second issue involves every supported version of Windows, ranging from Windows 2000, XP and Vista to Server 2003 and Server 2008. "You may experience issues with UDP-dependent network services after you install the Domain Name System (DNS) Server service security update 953230 (MS08-037) and then restart the computer," Microsoft said.

In both instances, Microsoft offered work-arounds in the support documents but did not say whether, or when, the original DNS patch would be re-released. In response to questions, a company spokesman today said, "Microsoft currently has no plans to reissue MS08-037.

Robert McMillan of the IDG News Service contributed to this story.

Read more about networking and internet in Computerworld's Networking and Internet Knowledge Center.



Jump to comments

DNS

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

What People Are Saying

White Papers & Webcasts

Death to PST Files
Download Now  

Business Process Framework Demo
Learn about Configurable Business Processes and Calculated Fields. Watch Now!

A Green Architectural Strategy That Puts IT in the Black
Levergage green computing across your data center. Read more now.  

Manager Experience Demo
Go beyond self-service solutions to perform more effectively. Watch Now.

Quantifying the Business Value of VMware View
Learn why you should invest in a centralized virtual desktop.  

Asia-Pacific Enterprise Network Solutions
Learn through this Webcast how your business can achieve reliability, performance and value in hard-to-reach locations within the Asia-Pacific region.

Mainsoft Webcast w/ Forrester Research: Drive SharePoint Adoption in Lotus Notes Shops
How can you drive mainstream user adoption of Microsoft SharePoint when your users rely on Lotus Notes?

Disaster Recovery & Cost Savings Zone
Thousands of customers world-wide have turned to virtualization solutions from Riverbed as a way to reduce costs.



IT Jobs