US-CERT Warns of Impending DNS Cache Poisoning

LOS ANGELES — The United States Computer Emergency Readiness Team (US-CERT) is warning website owners and operators about deficiencies in the Domain Name Server (DNS) protocol which may leave affected systems vulnerable to DNS cache poisoning attacks.

According to US-CERT, if an attacker can successfully conduct a cache poisoning attack, it may be able to cause a nameserver's clients to contact an incorrect, and possibly malicious, host. This may allow an attacker to obtain sensitive information or mislead users into believing they are visiting a legitimate website when they have in fact been redirected elsewhere.

This vulnerability may be of particular concern to high-traffic adult website operators that could be targeted in an attempt to steer visitors to rogue affiliate sites.

US-CERT is concerned that recent public postings regarding this vulnerability will provide attackers with the technical details that are required to exploit it, and as such are encouraging users to patch vulnerable systems immediately.

A document entitled "VU#800113 - Multiple DNS implementations vulnerable to cache poisoning" lists solutions to mitigate the risks, including placing the nameserver outside of the NAT/PAT device in the network infrastructure; configuring the NAT/PAT device to perform source port randomization; and configuring the NAT/PAT device to preserve the source port assigned by the nameserver.

While some of the patches implement source port randomization in the name server as a way to reduce the practicality of cache poisoning attacks, US-CERT cautions administrators that in infrastructures where nameservers exist behind Network Address Translation (NAT) and Port Address Translation (PAT) devices, port randomization in the nameserver may be overwritten by the NAT/PAT device and a sequential port address could be allocated, weakening the protection offered by source port randomization in the nameserver.

US-CERT will provide additional information as it becomes available.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

X3 Expo Unveils 2026 All-Stars, Show Dates Set for Jan. 16-17

X3 Expo returns to the historic Hollywood Palladium on January 16–17, bringing together fans, creators and industry insiders for North America’s largest assembly of adult entertainment stars, alongside a dazzling lineup of attractions spotlighting the cutting edge of modern media and pleasure tech.

Trump Administration Issues Executive Order Against 'Debanking'

The White House on Thursday issued an executive order limiting financial institutions’ ability to restrict access to financial services for people or groups involved in lawful industries, a longtime goal of adult industry advocates and stakeholders.

Go.cam Launches Free Age Verification Solution, Anti-Fraud Features

Go.cam has announced that its age verification solution is now free with updated anti-fraud and identity protection features.

Florida AG Sues EU-Based Adult Companies for Failing to Age-Verify Users

Florida Attorney General James Uthmeier filed a lawsuit Monday with the 12th Judicial Circuit Court of Florida against five EU-based adult companies for allegedly failing to require age verification before allowing access to adult content.

SkyPrivate Launches 'Telegram Pay-Per-Minute' Feature

SkyPrivate has launched a new pay-per-minute (PPM) private show option on Telegram.

Pineapple Support to Host 'Money and Mental Health' Online Event

Pineapple Support is hosting a free, online event to help performers balance financial wellbeing with mental health, Aug. 18-19.

Arcom Warns 5 Adult Sites Over Age Verification

French media regulator Arcom has sent enforcement notices to the operators of five adult websites that the agency says have failed to implement age verification as required under France’s Security and Regulation of the Digital Space (SREN) law.

MojoHost Debuts NVIDIA Blackwell-Powered Hosting

MojoHost has announced the launch of NVIDIA Blackwell-powered hosting featuring RTX 6000 Pro MaxQ GPUs.

FSC: Identity Theft Targeting Adult Performers

The Free Speech Coalition has put out an alert warning of an individual found to be targeting adult performers for identity theft.

Assylum.com Implements New Age Verification System

Assylum.com has introduced an age verification system across its member sites.

Show More