cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1954
Views
0
Helpful
2
Replies

xfinity dns cache poisoning events?

Pat Fahey
Level 1
Level 1

Seeing a lot of these events in the log:

PROTOCOL-DNS potential dns cache poisoning attempt - mismatched txid (3:21355:5)

 

Firepower seems to be finding something about xfinity DNS (75.75.75.75, 75.75.76.76) that it does not like.

 

Has anyone found a good way to deal with the messages?

 

Thanks for your help.

----------------------------------------------

UPDATE:  The message indicates an earlier DNS message format that can be exploited.  I solved the problem by disabling the rule. 

2 Replies 2

Bogdan Nita
VIP Alumni
VIP Alumni

It might also indicate that somebody is trying to poison the dns cache.

DNS uses only a 16-bit transaction ID to check the response is valid, although most of the dns servers today will check the TXID is valid a lot of dns responses with false TXID could indicate that somebody is trying to guess the value.

https://www.cs.cornell.edu/~shmat/shmat_securecomm10.pdf

 

HTH

Bogdan

I'll turn the rule back on and try to capture the packets next time it hits.

Review Cisco Networking for a $25 gift card