DNS Gives Hackers Global Access To All Internet Devices

16 November 2018by Abdallah Alhajeid

The Domain Name System (DNS) has been an essential component of the functionality of the Internet since 1985. This remarkable technology enables internet services and the World Wide Web to be globally available to billions of users. DNS acts as the ‘internet phone book’ by providing a worldwide, distributed directory service. Developed by John Postel and Paul Mockapetris as an ‘open’ system for use in government and public sector organisations, little thought was given to security at the time or in the future. Given its role in providing a connection to every internet device in the world. It has always been a prime target for cyber attack by criminals and nation-state actors.

 

Why is DNS important?

The job of DNS is to translate web domain names into the numerical IP addresses needed to locate the services running on another computer or server. It converts human-readable addresses like “google.com” to computer-readable IP addresses like “173.194.67.102”. Unlike a phone book, DNS can be quickly updated, allowing a service’s location on the network to change without affecting the end user.

 

It’s big and complicated

DNS is a hierarchical decentralised naming system that specifies a database service, data structures and the communication services used as part of the Internet Protocol Suite. With billions of devices and IP addresses to accommodate, the system is delivered by many interconnected ‘DNS servers’ operated by national and commercial organisations throughout the world. Handling a theoretical capacity of 4 billion unique addresses (IPv4), its scale and efficiency are astonishing. Consistent with the multi-year rollout of IPv6, it is currently being adapted to accommodate 340 undecillion unique IP addresses in the future!

 

How is DNS exploited by a hacker?

The SANS 2017 Data Protection Survey confirmed that over 75% of businesses reported two or more different types of DNS-based threats to their data in 2017 with attacks such as ransomware, DDoS and data exfiltration among the most common.

 

Examples of DNS cyber attacks include:

 

DNS spoofing/cache poisoning

Corrupt data is introduced into the DNS resolver’s cache, causing the name server to return an incorrect result record, e.g. an IP address. This results in traffic being diverted away from the legitimate server towards a fake server set up by the hacker.

 

DNS tunnelling

Undetected by most firewalls, attackers use protocols such as SSH, TCP, or HTTP to pass malware or stolen information into DNS queries.

 

DNS hijacking

Targeting the DNS record of a website, the attacker redirects queries to a different domain name server.

 

DNS flood

Attacks such as NXDOMAIN use botnets to inundate a DNS server with requests, asking for records that don’t exist and attempting to cause a distributed denial-of-service (DDoS) for legitimate traffic.

 

Preventing DNS Attacks

Reviewing and configuring secure DNS is an essential part of the effective cyber security management for any organisation. While smaller firms may only be using the services of ISP’s or outsourced support companies, they should be at least be aware of the dangers of DNS attack. Larger firms running their on-premise or cloud servers should be taking pro-active steps to secure and harden all their DNS resources.

The cyber intelligence specialists, Security Trails recommends the following ‘8 tips to prevent DNS attack’:

  1. Audit all DNS resources regularly
  2. Keep DNS server software updated
  3. Hide and stop hackers from identifying the version of DNS software running
  4. Restrict all DNS zone transfers
  5. Disable DNS recursion to prevent DNS poisoning attacks
  6. Use isolated DNS servers if possible
  7. Use a DDoS mitigation provider like Cloudflare
  8. Secure access to any cloud DNS or DDoS mitigation service using 2FA

 

The Future

The DNS Security Extensions protocol (DNSSEC) is widely accepted as the long-term solution to securing DNS. DNSSEC creates a secure domain name system by adding cryptographic signatures to existing DNS records. It protects against attacks by digitally signing data to help ensure its validity. In order to ensure a secure lookup, the signing must happen at every level in the DNS lookup process. While a powerful solution, DNS and ISP providers have not yet universally adopted this approach.

 

——————–

As an experienced cyber security solution provider, Wizard Cyber is a specialist in helping companies protect themselves from DNS cyber attacks. Our services include regular DNS audits, DNS server hardening and the management of DDoS mitigation services from vendor partners such as Cloudflare and Imperva.

Abdallah Alhajeid

WordPress Developer

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation