module

BIND TSIG Query Denial of Service

Disclosed
Sep 27, 2016
Created
May 30, 2018

Description

A defect in the rendering of messages into packets can cause named to
exit with an assertion failure in buffer.c while constructing a response
to a query that meets certain criteria.

This assertion can be triggered even if the apparent source address
isn't allowed to make queries.

Authors

Martin Rocha
Ezequiel Tavella
Alejandro Parodi
Infobyte Research Team

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use auxiliary/dos/dns/bind_tsig
msf auxiliary(bind_tsig) > show actions
...actions...
msf auxiliary(bind_tsig) > set ACTION < action-name >
msf auxiliary(bind_tsig) > show options
...show and set options...
msf auxiliary(bind_tsig) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.