lost and found ( for me ? )

Showing posts with label BIND9. Show all posts
Showing posts with label BIND9. Show all posts

BIND : view queries logs with bindgraph

Here’s how to install bindgraph to monitor queries log with GUI ( RRD graph ).
root@ubuntu1204-vm1:~# tail -1 /etc/lsb-release
DISTRIB_DESCRIPTION="Ubuntu 12.04.2 LTS"
root@ubuntu1204-vm1:~# uname -ri
3.2.0-44-generic x86_64

install bind9 and bindgraph via apt-get
root@ubuntu1204-vm1:~# apt-get install bind9 bindgraph



root@ubuntu1204-vm1:~# bindgraph.pl --version
bindgraph 0.2 by {dela,md}@linux.it
root@ubuntu1204-vm1:~# named -version
BIND 9.8.1-P1

[ bindgraph ]

bindgraph configuration file.
I used default config.
root@ubuntu1204-vm1:~# less /etc/default/bindgraph
DNS_LOG=/var/log/bind9-query.log
LOG_FORMAT=bind93

[ bind ]

enable queries log
root@ubuntu1204-vm1:~# cat /etc/bind/named.conf.options
options {
directory "/var/cache/bind";
version none;
auth-nxdomain no;    # conform to RFC1035
# listen-on-v6 { any; };
listen-on-v6 { none; };
recursion yes;
};

# enable queries log for bindgraph
logging {
       channel "log_queries" {
               file "/var/log/bind9-query.log";
               severity info;
               print-time yes;
               print-category yes;
       };

       category queries { "log_queries"; };
};

create a query log file and change file owner
root@ubuntu1204-vm1:~# touch /var/log/bind9-query.log
root@ubuntu1204-vm1:~# chown bind:bind /var/log/bind9-query.log

restart bind9
root@ubuntu1204-vm1:~# service bind9 restart

confirm if query logging is enabled.
root@ubuntu1204-vm1:~# rndc status
version: 9.8.1-P1 (version.bind/txt/ch disabled)
CPUs found: 2
worker threads: 2
number of zones: 18
debug level: 0
xfers running: 0
xfers deferred: 0
soa queries in progress: 0
query logging is ON
recursive clients: 0/0/1000
tcp clients: 0/100
server is up and running

[ apache ]

install apache to view DNS queries graph via web browser
root@ubuntu1204-vm1:~# apt-get install apache2

cgi for bindgraph has been installed under /usr/lib/cgi-bin/
root@ubuntu1204-vm1:~# dpkg -L bindgraph | grep -i cgi
/usr/lib/cgi-bin
/usr/lib/cgi-bin/bindgraph.cgi

I used default httpd configuration.
# cat /etc/apache2/sites-available/default
<VirtualHost *:80>
ServerAdmin webmaster@localhost

DocumentRoot /var/www
<Directory />
Options FollowSymLinks
AllowOverride None
</Directory>
<Directory /var/www/>
Options Indexes FollowSymLinks MultiViews
AllowOverride None
Order allow,deny
allow from all
</Directory>

ScriptAlias /cgi-bin/ /usr/lib/cgi-bin/
<Directory "/usr/lib/cgi-bin">
AllowOverride None
Options +ExecCGI -MultiViews +SymLinksIfOwnerMatch
Order allow,deny
Allow from all
</Directory>

ErrorLog ${APACHE_LOG_DIR}/error.log

# Possible values include: debug, info, notice, warn, error, crit,
# alert, emerg.
LogLevel warn

CustomLog ${APACHE_LOG_DIR}/access.log combined

   Alias /doc/ "/usr/share/doc/"
   <Directory "/usr/share/doc/">
       Options Indexes MultiViews FollowSymLinks
       AllowOverride None
       Order deny,allow
       Deny from all
       Allow from 127.0.0.0/255.0.0.0 ::1/128
   </Directory>

</VirtualHost>
root@ubuntu1204-vm1:~#

start bindgraph and httpd
# service bindgraph restart
# service apache2 restart

start an web browser and access to http:// your BIND server IP/cgi-bin/bindgraph.cgi
If you can’t see the graph , please type the following command and then access to your BIND.
This might help you diagnose problems.. ( this is as-is based info … )
root@ubuntu1204-vm1:~# /usr/bin/perl -w /usr/sbin/bindgraph.pl -l /var/log/bind9-query.log --format=bind93 -d --daemon_rrd=/var/lib/bindgraph --rrd_name=bindgraph

root@ubuntu1204-vm1:~# ll -d /var/lib/bindgraph/*
-rw-r--r-- 1 root root 7106208  5月 31 02:48 /var/lib/bindgraph/bindgraph.rrd

DNSSEC: BIND9 managed-kes オプション

[root@hat3 ~]# cat /etc/redhat-release
CentOS release 5.4 (Final)

9.7からこんなオプションができたんだ。。

managed-keys オプション

For BIND 9.7 and later versions, using a managed-key allows automatic tracking of the key using a protocol known as RFC-5011.

https://www.isc.org/software/bind/new-features/9.7

Automated trust anchor maintenance for DNSSEC (RFC 5011)

RFC 5011, Automated Updates of DNS Security (DNSSEC) Trust Anchors, documents a method for automated, authenticated, and authorized updating of DNSSEC "trust anchors" especially for the use of multiple islands of trust.
The new managed-keys statement provides named with trusted keys which are automatically kept up to date using RFC 5011. It differs from the trusted-keys statement with an additional field (second field) containing initial-key keyword which means only use this key the first time.named stores keys in a managed keys database.

[root@hat3 ~]# /usr/local/sbin/named -v
BIND 9.7.1-P2

適当な手段で鍵を登録。

[root@hat3 ~]# dig @127.1 . dnskey | grep 257 > dnskey

[root@hat3 ~]# cat dnskey
.                       86056   IN      DNSKEY  257 3 8 AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQbSEW0O8gcCjF FVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh/RStIoO8g0NfnfL2MTJRkxoX bfDaUeVPQuYEhg37NZWAJQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaD X6RS6CXpoY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3LQpz W5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGOYl7OyQdXfZ57relS Qageu+ipAdTTJ25AsRTAoub8ONGcLmqrAmRLKBP1dfwhYB4N7knNnulq QxA+Uk1ihz0=

[root@hat3 ~]# cat /etc/named.conf
options {
       directory "/var/named";
       max-cache-size 10M;
       recursion yes;
       dnssec-enable yes;
       dnssec-validation yes;
};

zone "." in {
       type hint;
       file "named.ca";
};

key "rndckey" {
     algorithm hmac-md5;
     secret "3dpawGP95zWKVzj8SDhX1w==";
};

controls {
     inet 127.0.0.1 port 953
             allow { 127.0.0.1; } keys { "rndckey"; };
};

managed-keys {
"." initial-key 257 3 8 "AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQbSEW0O8gcCjF FVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh/RStIoO8g0NfnfL2MTJRkxoX bfDaUeVPQuYEhg37NZWAJQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaD X6RS6CXpoY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3LQpz W5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGOYl7OyQdXfZ57relS Qageu+ipAdTTJ25AsRTAoub8ONGcLmqrAmRLKBP1dfwhYB4N7knNnulq QxA+Uk1ihz0=";
};
[root@hat3 ~]#

[root@hat3 ~]# /usr/local/sbin/named

パーミッションのエラーが。

hat3 named[10171]: could not open file '/var/run/named/named.pid': Permission denied
hat3 named[10171]: could not open file '/var/run/named/session.key': Permission denied
hat3 named[10171]: could not create /var/run/named/session.key

named.pid , session.key の保存場所を変更

[root@hat3 ~]# egrep '(pid|session)' /etc/named.conf
       pid-file "/var/named/named.pid";
       session-keyfile "/var/named/session.key";

[root@hat3 ~]# /usr/local/sbin/named

ワーキングディレクトリ ( /var/named ) に managed* と session.key ができた。

[root@hat3 named]# pwd
/var/named
[root@hat3 named]#
[root@hat3 named]# ls
managed-keys.bind  managed-keys.bind.jnl  named.ca  named.pid  session.key
[root@hat3 named]#

managed* は named stores keys in a managed keys database. のことかな。

[root@hat3 named]# cat managed-keys.bind
$ORIGIN .
$TTL 0  ; 0 seconds
@                       IN SOA  . . (
                               2          ; serial
                               0          ; refresh (0 seconds)
                               0          ; retry (0 seconds)
                               0          ; expire (0 seconds)
                               0          ; minimum (0 seconds)
                               )
                       KEYDATA 20100813181024 20100813061024 19700101000000 257 3 8 (
                               AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQ
                               bSEW0O8gcCjFFVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh
                               /RStIoO8g0NfnfL2MTJRkxoXbfDaUeVPQuYEhg37NZWA
                               JQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaDX6RS6CXp
                               oY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3
                               LQpzW5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGO
                               Yl7OyQdXfZ57relSQageu+ipAdTTJ25AsRTAoub8ONGc
                               LmqrAmRLKBP1dfwhYB4N7knNnulqQxA+Uk1ihz0=
                               ) ; key id = 19036
[root@hat3 named]#

[root@hat3 named]# cat managed-keys.bind.jnl
;BIND LOG V9
8[root@hat3 named]#


session.key は DDNS 用っぽい。

Simplified configuration of Dynamic DNS
For easier automatic re-signing, you just need to have the zone be dynamic and have the keys accessible.
The update-policy zone option has been extended to add a local setting to enable Dynamic DNS for a zone. named will generate a TSIG session key known as local-ddns at startup which will be used for these updates. The session key file defaults to /var/run/named/session.key or can be defined using the session-keyfile option.

[root@hat3 named]# cat session.key
key "local-ddns" {
       algorithm hmac-sha256;
       secret "kD4PsVav+kw3X/vOyEeLZnfCQQjeEE0q/wMERmD+X2M=";
};
[root@hat3 named]#

適当に時間が経過して 鍵のアップデートが必要になったら、鍵更新を自動でしてくれるのかなー。
うーん、BIND 9.7 さわってないのでチェックせねば。。。

RFC5011でググったら、こんなコメントが。ふーん。

http://jpinfo.jp/mail/backnumber/event/0082.html

Trust AnchorとはDNSSECによる検証を行う場合に最初の手がかりとなる情報で
あり、DNSSECによる名前検証を行うにあたり、必須となるものです。DNSSECの 仕様では、Trusted AnchorがすべてのDNSキャッシュサーバに設定され、かつ適 切な間隔で更新され続ける必要があります。 Trusted Anchorの更新を自動的に行うためのプロトコル仕様は、RFC 5011によ り規定されています。しかし、RFC 5011で規定されているのは自動更新のプロ トコル仕様のみであり、実際のインターネットにおいて自動更新を具体的にど のように運用するかについては規定されていません。

続の続(Final?): BIND9 脆弱性: Dynamic Update DoS

Protect against DDNS DoS w/ iptables ( ( not rage against the machine ! )

こんなコメントみつけた。

the exploit is clearly in active use ってコメント気になる。。

| iptables -A INPUT -p udp --dport 53 -j DROP -m u32 --u32 '30>>27&0xF=5'

Works for me, but no guaranty. I have added a second rule which logs
said dnsupdate packets and i already got several such packets from the
outside world, so the exploit is clearly in active use and the least you
can do is to try the iptables rule.


テスト構成図
DDNS iptablesでDrop
arizona ( DDNS ,192.168.1.150) --------> alaska ( BIND 9.6.1 , 192.168.1.200 )

その前に、alaska マシンには、必要な perl module(Net::DNS)がなかった。
CPANじゃなくて、yum で perl modules をインストールしよう。

両マシンとも Fedora

[root@arizona ~]# cat /etc/redhat-release
Fedora release 11 (Leonidas)
[root@arizona ~]# uname -r
2.6.29.6-213.fc11.i686.PAE


[root@alaska ~]# cat /etc/redhat-release
Fedora release 11 (Leonidas)
[root@alaska ~]# uname -r
2.6.29.6-213.fc11.i686.PAE
[root@alaska ~]#

[root@alaska ~]# LANG=C yum grouplist
Loaded plugins: refresh-packagekit
Setting up Group Process
Installed Groups:
Administration Tools
Arabic Support
Armenian Support

Virtualization
Web Server
X Software Development
X Window System
Available Groups:
Afrikaans Support

Perl Development

Zulu Support
Done
[root@alaska ~]#

[root@alaska ~]# yum -y groupinstall "Perl Development"

あっ、肝心の Net::DNS インストールされてない。。

[root@alaska ~]# ./localhost_sleep_tight_bind9.pl
Can't locate Net/DNS.pm in @INC (@INC contains: /usr/local/lib/perl5/site_perl/5.10.0/i386-linux-thread-multi /usr/local/lib/perl5/site_perl/5.10.0 /usr/lib/perl5/vendor_perl/5.10.0/i386-linux-thread-multi /usr/lib/perl5/vendor_perl/5.10.0 /usr/lib/perl5/vendor_perl /usr/lib/perl5/5.10.0/i386-linux-thread-multi /usr/lib/perl5/5.10.0 /usr/lib/perl5/site_perl .) at ./localhost_sleep_tight_bind9.pl line 3.
BEGIN failed--compilation aborted at ./localhost_sleep_tight_bind9.pl line 3.

別マシン ( arizona )はインストールされてたなー。もしかして smokeping インストールしたときに Net::DNS インストールされたような気がしないわけでもないような気がする今日この頃。

[root@alaska ~]# perl -MCPAN -e shell
cpan[1]> install Net::DNS

脆弱性のあるバージョン

[root@alaska ~]# named -v
BIND 9.6.1

[root@alaska ~]# named

[root@alaska ~]# ./localhost_sleep_tight_bind9.pl

alaska named[11883]: db.c:649: REQUIRE(type != ((dns_rdatatype_t)dns_rdatatype_any)) failed
alaska named[11883]: exiting (due to assertion failure)

では、やっとこ iptables へ。

[root@alaska ~]# iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination
ACCEPT udp -- anywhere anywhere udp dpt:domain
ACCEPT tcp -- anywhere anywhere tcp dpt:domain
ACCEPT udp -- anywhere anywhere udp dpt:bootps
ACCEPT tcp -- anywhere anywhere tcp dpt:bootps

Chain FORWARD (policy ACCEPT)
target prot opt source destination
ACCEPT all -- anywhere 192.168.122.0/24 state RELATED,ESTABLISHED
ACCEPT all -- 192.168.122.0/24 anywhere
ACCEPT all -- anywhere anywhere
REJECT all -- anywhere anywhere reject-with icmp-port-unreachable
REJECT all -- anywhere anywhere reject-with icmp-port-unreachable

Chain OUTPUT (policy ACCEPT)
target prot opt source destination

[root@alaska ~]# iptables -A INPUT -p udp --dport 53 -j DROP -m u32 --u32 '30>>27&0xF=5'

追加された。

[root@alaska ~]# iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination
ACCEPT udp -- anywhere anywhere udp dpt:domain
ACCEPT tcp -- anywhere anywhere tcp dpt:domain
ACCEPT udp -- anywhere anywhere udp dpt:bootps
ACCEPT tcp -- anywhere anywhere tcp dpt:bootps
DROP udp -- anywhere anywhere udp dpt:domain u32 0x1e>>0x1b&0xf=0x5


では try again !

[root@alaska ~]# named
[root@alaska ~]# iptables -A INPUT -p udp --dport 53 -j DROP -m u32 --u32 '30>>27&0xF=5'

こんなイメージで DDNS を arizona から alaska へ。

DDNS Drop
arizona ( DDNS , 192.168.1.150 ) --------> alaska ( BIND 9.6.1 , 192.168.1.200 )

[root@arizona ~]# ./localhost_sleep_tight_bind9.pl
[root@arizona ~]# ./ptr.localhost_sleep_tight_bind9.pl
[root@arizona ~]# ./foo.bar_sleep_tight_bind9.pl
[root@arizona ~]# ./ptr.foo.bar_sleep_tight_bind9.pl

BIND上でキャプチャ

[root@alaska ~]# tshark -i eth0 port 53
Running as user "root" and group "root". This could be dangerous.
Capturing on eth0
0.000000 192.168.1.150 -> 192.168.1.200 DNS Dynamic update SOA localhost
113.579449 192.168.1.150 -> 192.168.1.200 DNS Dynamic update SOA 0.0.127.in-addr.arpa
122.431512 192.168.1.150 -> 192.168.1.200 DNS Dynamic update SOA foo.bar
135.062697 192.168.1.150 -> 192.168.1.200 DNS Dynamic update SOA 0.168.192.in-addr.arpa

おっ、BIND いきてる。ドロップしているみたい。
iptables のログの出しかた忘れたー。

[root@alaska ~]# rndc status
version: 9.6.1
number of zones: 16
debug level: 0
xfers running: 0
xfers deferred: 0
soa queries in progress: 0
query logging is OFF
recursive clients: 0/0/1000
tcp clients: 0/100
server is up and running

iptables が有効がきいているかどうか、iptables の情報をフラッシュして、トライ。
これでBINDがダウンすれば、iptables の効果がきいていると考えられる。

[root@alaska ~]# iptables -F
[root@alaska ~]# iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination

Chain FORWARD (policy ACCEPT)
target prot opt source destination

Chain OUTPUT (policy ACCEPT)
target prot opt source destination
[root@alaska ~]#

arizona から攻撃、。

[root@arizona ~]# ./localhost_sleep_tight_bind9.pl

alaska ( BIND ) チェック。

しんだっぽい。

[root@alaska ~]# rndc status
rndc: connect failed: 127.0.0.1#953: connection refused

おー、やっぱり iptables ではじいてたみたいだ。

alaska named[12162]: db.c:649: REQUIRE(type != ((dns_rdatatype_t)dns_rdatatype_any)) failed
alaska named[12162]: exiting (due to assertion failure)

iptables 勉強しよう、、かな、、いや、、面倒。。。

Cheers!