A critical flaw allows hacking Linux machines with just a malicious DNS Response

Discussion in 'all things UNIX' started by lotuseclat79, Jun 29, 2017.

  1. lotuseclat79

    lotuseclat79 Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    5,390
  2. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,199
  3. mirimir

    mirimir Registered Member

    Joined:
    Oct 1, 2011
    Posts:
    9,252
    Charming. In Debian jessie:
    Code:
    $ systemctl status systemd-resolved
    ● systemd-resolved.service - Network Name Resolution
       Loaded: loaded (/lib/systemd/system/systemd-resolved.service; disabled)
       Active: inactive (dead)
         Docs: man:systemd-resolved.service(8)
     
  4. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,199
    Yep, same here in Fedora 25:
    Code:
    ● systemd-resolved.service - Network Name Resolution
       Loaded: loaded (/usr/lib/systemd/system/systemd-resolved.service; disabled; vendor preset: disabled)
       Active: inactive (dead)
         Docs: man:systemd-resolved.service(8)
               http://www.freedesktop.org/wiki/Software/systemd/resolved
               http://www.freedesktop.org/wiki/Software/systemd/writing-network-configuration-managers
               http://www.freedesktop.org/wiki/Software/systemd/writing-resolver-clients
     
  5. dogbite

    dogbite Registered Member

    Joined:
    Dec 13, 2012
    Posts:
    1,290
    Location:
    EU
  6. Mrkvonic

    Mrkvonic Linux Systems Expert

    Joined:
    May 9, 2005
    Posts:
    10,228
    The one thing that matters here is - attacker-controlled DNS service.
    This narrows does the problem.
    Mrk
     
  7. NormanF

    NormanF Registered Member

    Joined:
    Feb 20, 2009
    Posts:
    2,883
    Yup - but its not enabled by default in Linux so the exploit is of theoretical interest.
     
  8. fblais

    fblais Registered Member

    Joined:
    Jul 31, 2008
    Posts:
    1,341
    Location:
    Québec, Canada
    Disabled in Xubuntu 16.04.
     
  9. MsFluffyMuffin

    MsFluffyMuffin Registered Member

    Joined:
    Jun 4, 2003
    Posts:
    70
    Location:
    UK
    Also disabled in Linux Mint 18.1 Cinnamon :)

    $ systemctl status systemd-resolved
    ● systemd-resolved.service - Network Name Resolution
    Loaded: loaded (/lib/systemd/system/systemd-resolved.service; disabled; vendo
    Active: inactive (dead)
    Docs: man:systemd-resolved.service ( 8 ) :
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.