{"id":16829,"date":"2019-11-07T10:52:27","date_gmt":"2019-11-07T18:52:27","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/11\/07\/news-10568\/"},"modified":"2019-11-07T10:52:27","modified_gmt":"2019-11-07T18:52:27","slug":"news-10568","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/11\/07\/news-10568\/","title":{"rendered":"VB2019 paper: DNS on fire"},"content":{"rendered":"<p>The &#8220;phonebook of the Internet&#8221; has well outlived physical phonebooks, but that doesn&#8217;t mean DNS is without its issues. There is a joke among incident responders that, even when you&#8217;re sure the problem isn&#8217;t DNS, it still ends up being DNS.<\/p>\n<p>Aside from configuration issues, DNS is also a very valuable target for adversaries. In a paper presented at VB2019, <em>Cisco Talos<\/em> researchers Warren Mercer and Paul Rascagn\u00e8res looked at two recent attacks against DNS infrastructure: DNSpionage and Sea Turtle. The latter attack involved the compromise of one country&#8217;s DNS registry.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" style=\"display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/www.virusbulletin.com\/files\/7515\/7312\/4039\/DNS-on-fire-fig8.png\" alt=\"DNS-on-fire-fig8.png\" width=\"640\" height=\"298\" \/><span class=\"centered-caption\">April 2019 Sea Turtle victimology map.<\/span>The Sea Turtle research also won the researchers and their team the sixth annual P\u00e9ter Sz<span>\u0151<\/span>r Award; they received the award during the VB2019 gala dinner.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"framed\" style=\"display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/www.virusbulletin.com\/files\/cache\/8da9e34d06d7221cf736579d429e7981_f4034.JPG\" alt=\"peter-szor-award-2019.JPG\" width=\"580\" height=\"355\" \/><span class=\"centered-caption\">Warren and Paul were presented with the award during the VB2019 gala dinner.<\/span><br \/>Today we publish Warren and Paul&#8217;s paper in both <a title=\"VB2019 paper: DNS on fire\" href=\"https:\/\/www.virusbulletin.com\/virusbulletin\/2019\/11\/vb2019-paper-dns-fire\/\">HTML<\/a> and <a href=\"https:\/\/www.virusbulletin.com\/uploads\/pdf\/magazine\/2019\/VB2019-Mercer-Rascagneres.pdf\" target=\"_blank\">PDF <\/a>format. We have also uploaded the video of thier VB2019 presentation to our <em>YouTube<\/em> channel.<\/p>\n<p>\u00a0<\/p>\n<p>\u00a0<\/p>\n<p style=\"text-align: center;\" width=\"100%\" height=\"420\"><iframe loading=\"lazy\" src=\"https:\/\/www.youtube.com\/embed\/ws1k44ZhJ3g\" frameborder=\"0\" width=\"100%\" height=\"420\" style=\"\"> <\/iframe><\/p>\n<p>\u00a0<\/p>\n<p>outertext<br \/><a href=\"https:\/\/www.virusbulletin.com\/blog\/2019\/11\/vb2019-paper-dns-fire\/\" target=\"bwo\" >https:\/\/www.virusbulletin.com\/rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.virusbulletin.com\/files\/7515\/7312\/4039\/DNS-on-fire-fig8.png\"\/><br \/>                                 In a paper presented at VB2019, Cisco Talos researchers Warren Mercer and Paul Rascagneres looked at two recent attacks against DNS infrastructure: DNSpionage and Sea Turtle. Today we publish their paper and the recording of their presentation.                <\/p>\n<p>                 <a href=\"https:\/\/www.virusbulletin.com\/blog\/2019\/11\/vb2019-paper-dns-fire\/\">Read more<\/a>                                <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[23177,10378,23176],"tags":[],"class_list":["post-16829","post","type-post","status-publish","format-standard","hentry","category-magazine","category-security","category-virusbulletin"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16829","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=16829"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16829\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=16829"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=16829"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=16829"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}