home.social

#dnssecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #dnssecurity, aggregated by home.social.

fetched live
  1. Stop waking up to a DNS hijack at 3 AM. This senior sysadmin guide walks you through deploying DoH and DoT internally — tradeoffs, cert management, and hardening. #DNSSecurity #DevSecOps #NetworkHardening

    valtersit.com/guides/networkin

  2. Edit: Es lag an einer abgelaufenen DNSSEC Signatur (DNSSEC war nicht aktiviert, daher seltsam). Details siehe in den weiteren Kommentaren

    Seit heute morgen lässt sich unter vielen DNS Servern die Hauptdomain meines Servers nicht mehr aufrufen und ich verstehe noch nicht wieso.

    Hintergrund: Es ist der gleiche Server wie dieser GoToSocial Fedi Server.
    Ich habe die Konfiguration in den letzten Monaten nicht angerührt.

    DNS Settings beim Provider unverändert korrekt.
    DNS Check für meine Hauptdomain zeigt, dass sie in DE nicht mehr erreichbar ist.

    Gibt es gerade weltweite DNS Störungen? Ich habe nichts mitbekommen und bin ratlos.

    Besonders dumm: Meine Familie nutzt den Mailserver über die Hauptdomain und kommt ohne ausländische DNS Server (oder Drillisch/1&1 Mobilfunk) nicht mehr ohne Tweaks an die Mails ran.

    #dns #admin #störungsinformationsmanagement #dnssecurity

  3. Numerologie in Domainnamen: Wie eine ungewöhnliche Basis-5-Kodierung drei Malware-Kampagnen als eine entlarvt

    Wer Domains in großem Umfang registriert, hinterlässt Spuren – in der Infrastruktur, im verwendeten Vokabular, aber vor allem in den Zahlen.

    all-about-security.de/numerolo

    #dns #DNSsecurity #malware #itsecurity #itsicherheit #cybersecurity #cybersicherheit

  4. DNS-Ausfall legt 17,7 Millionen .de-Domains lahm

    Ursache war keine externe Attacke, sondern eine technische Störung im DNS-Dienst der DENIC eG, der in Frankfurt ansässigen Genossenschaft, die Deutschlands nationale Top-Level-Domain .de verwaltet. Die Registrierungsstelle bestätigte das Problem unmittelbar nach Bekanntwerden.

    all-about-security.de/dns-ausf

    #denic #DNS #DNSsecurity #cybersecurity #itsicherheit

  5. Infoblox Managed Rules für AWS Network Firewall: DNS-basierter Schutz gegen Phishing und C2-Angriffe

    Mit den Infoblox Managed Rules für die AWS Network Firewall steht Kunden nun ein zusätzlicher, vorgelagerter Schutz auf DNS-Ebene zur Verfügung – vollständig in die AWS-Konsole integriert und zunächst als kostenlose erweiterte Vorschau zugänglich.

    all-about-security.de/infoblox

    #aws #firewall #dns #dnssecurity #cloud

  6. Im Verborgenen: Wie Angreifer DNS-Einbettungsdienste zur Umgehung von Sicherheitskontrollen nutzen

    Die Analyse zeigt: Rund sieben Prozent aller täglich beobachteten Domains sind in zusammengesetzten DNS-Abfragen eingebettet – und entziehen sich damit herkömmlichen Sicherheitswerkzeugen.

    all-about-security.de/im-verbo

    #dns #dnssecurity #domains #cybersecurity

  7. NHS Scotland subdomains hijacked ⚠️
    • Adult content + illegal streams hosted
    • Likely DNS / WordPress compromise
    • Legacy infrastructure exploited

    Trust-based attacks are rising 👇

    technadu.com/nhs-scotland-doma

    #Infosec #Cybersecurity #DNSSecurity

  8. DNS-Hijacking durch Forest Blizzard: Wie Heimrouter zur Spionageinfrastruktur werden

    Microsoft Threat Intelligence identifizierte dabei über 200 betroffene Organisationen sowie rund 5.000 kompromittierte Endgeräte – und warnt, dass die eigentliche Unternehmensinfrastruktur dabei gar nicht direkt angegriffen werden muss.

    all-about-security.de/dns-hija

    #soho #DNS #dnssecurity #router #DHCP

  9. NIST SP 800-81r3: Was das neue DNS-Sicherheits-Framework für Unternehmen bedeutet

    Die Neufassung schließt eine jahrelange Lücke zwischen dem Stand der DNS-Technologie und den geltenden Empfehlungen – und stellt DNS erstmals klar als strategische Steuerungsebene moderner IT-Sicherheitsarchitekturen dar. Für Unternehmen, Behörden und IT-Verantwortliche ist die Publikation mehr als ein technisches Update

    all-about-security.de/nist-sp-

    #nist #framework #dns #dnssecurity #itsecurity #cybersecurity

  10. NIST SP 800-81r3: Was das neue DNS-Sicherheits-Framework für Unternehmen bedeutet

    Die Neufassung schließt eine jahrelange Lücke zwischen dem Stand der DNS-Technologie und den geltenden Empfehlungen – und stellt DNS erstmals klar als strategische Steuerungsebene moderner IT-Sicherheitsarchitekturen dar. Für Unternehmen, Behörden und IT-Verantwortliche ist die Publikation mehr als ein technisches Update

    all-about-security.de/nist-sp-

    #nist #framework #dns #dnssecurity #itsecurity #cybersecurity

  11. Hatte gedacht, installiere mal #pihole , andere deinen dns, und schau wie Werbung auf dem Handy geblockt wird. Pustekuchen, #ipv6 , #dnscache #chrome interner dns cache, #dnssecurity ... Die Installation von pihole war ein klaks, aber an allen Endgeräten und Router die Einstellungen so zu verbiegen dass pihole auch greifen kann dauert mir zu lange.
    #internetistkaputt

  12. Hatte gedacht, installiere mal #pihole , andere deinen dns, und schau wie Werbung auf dem Handy geblockt wird. Pustekuchen, #ipv6 , #dnscache #chrome interner dns cache, #dnssecurity ... Die Installation von pihole war ein klaks, aber an allen Endgeräten und Router die Einstellungen so zu verbiegen dass pihole auch greifen kann dauert mir zu lange.
    #internetistkaputt

  13. Schatten-DNS-Netzwerk nutzt kompromittierte Router für verdeckte Werbeumleitung

    Sicherheitsexperten haben ein ausgeklügeltes System entdeckt, das die DNS-Einstellungen von Routern manipuliert und Nutzer unbemerkt auf andere Websites umleitet.

    all-about-security.de/schatten

    #dnssecurity #dns #router #netzwerksicherheit #netzwerk

  14. KI-gestützte DNS-Sicherheit: Autoencoder-Technologie optimiert Tunneling-Erkennung

    Ein neues KI-basiertes Erkennungssystem identifiziert DNS-Tunneling-Angriffe mit einer Präzision von 99,9 Prozent.

    all-about-security.de/ki-gestu

    #dns #dnssecurity #autoencoder #cybersecurity #ki

  15. Secure your online presence with expert DNS protection - no shadow required! 😉 Skip the groundhog's guess and get guaranteed DNS reliability!

    DNSimple offers multi-layered DDoS defense and Anycast DNS across 200,000 managed domains.

    #DNSSecurity #ReliableDNS #DNS #DevOps

  16. Secure your online presence with expert DNS protection - no shadow required! 😉 Skip the groundhog's guess and get guaranteed DNS reliability!

    DNSimple offers multi-layered DDoS defense and Anycast DNS across 200,000 managed domains.

    #DNSSecurity #ReliableDNS #DNS #DevOps

  17. 🚨 Banks and insurance firms: Still on .com? You're missing out on instant trust and security with .BANK or .INSURANCE domains. These restricted TLDs signal security & legitimacy. Overwhelmed by requirements? DNSimple supports all security and compliance requirements, including #DNSSEC, #SSL, #MFA, real‑time #DDoS protection, vanity name servers, and expert support.
    Claim your .BANK or .INSURANCE domain today!
    Watch youtu.be/4dTbaSiag3s

    #BankDomain #InsuranceDomain #DNSSecurity

  18. 🚨 Banks and insurance firms: Still on .com? You're missing out on instant trust and security with .BANK or .INSURANCE domains. These restricted TLDs signal security & legitimacy. Overwhelmed by requirements? DNSimple supports all security and compliance requirements, including #DNSSEC, #SSL, #MFA, real‑time #DDoS protection, vanity name servers, and expert support.
    Claim your .BANK or .INSURANCE domain today!
    Watch youtu.be/4dTbaSiag3s

    #BankDomain #InsuranceDomain #DNSSecurity

  19. 🔐 Keep your domains safe and compliant. Whether you're managing a personal site or handling thousands of domains for a large corporation, DNSimple gives you access to the latest CAA record features to help keep your domains safe and compliant, more details in our blog blog.dnsimple.com/2025/05/new-

    #dns #dnssecurity #SSL #CAA #certificatmanagement

  20. 🔐 Keep your domains safe and compliant. Whether you're managing a personal site or handling thousands of domains for a large corporation, DNSimple gives you access to the latest CAA record features to help keep your domains safe and compliant, more details in our blog blog.dnsimple.com/2025/05/new-

    #dns #dnssecurity #SSL #CAA #certificatmanagement

  21. 🔐 Protect your domains from DNS takeover attacks with DNSimple’s new zone verification process. Discover how DNSimple’s zone verification feature adds an extra layer of protection against DNS takeover attacks making your domains safer than ever! Contact us for more details or read our blog 👉 blog.dnsimple.com/2025/05/zone
    #dns #dnssecurity #domainmanagement #cybersecurity

  22. 🔐 Protect your domains from DNS takeover attacks with DNSimple’s new zone verification process. Discover how DNSimple’s zone verification feature adds an extra layer of protection against DNS takeover attacks making your domains safer than ever! Contact us for more details or read our blog 👉 blog.dnsimple.com/2025/05/zone
    #dns #dnssecurity #domainmanagement #cybersecurity

  23. Schade, dass so etwas heute noch ein Angriffsszenario darstellen kann: "Hackers Can Hide Images in Text Data and Embeds Directly into DNS TXT Records". Zeit für #DNSSecurity & #ProtectiveDNS

    cybersecuritynews.com/hiding-i

  24. Of course it's DNS. 🤦🏻‍♂️ Attackers are turning DNS into a malware delivery pipeline. Instead of dropping files via email or sketchy links, they’re hiding payloads in DNS TXT records and reassembling them from a series of innocuous-looking queries. DOH and DOT make this even harder to monitor. DNS has always been a bit of a blind spot for defenders, and this technique exploits that perfectly. Also, yes, prompt injection payloads are now showing up in DNS records too. 🤬

    TL;DR
    ⚠️ Malware stored in DNS TXT records
    🧠 Chunked, hex-encoded, reassembled
    🔐 DOH/DOT encrypt lookup behavior
    🪄 Prompt injection payloads spotted too

    arstechnica.com/security/2025/
    #infosec #dnssecurity #malware #promptinjection #security #privacy #cloud #infosec #cybersecurity

  25. Of course it's DNS. 🤦🏻‍♂️ Attackers are turning DNS into a malware delivery pipeline. Instead of dropping files via email or sketchy links, they’re hiding payloads in DNS TXT records and reassembling them from a series of innocuous-looking queries. DOH and DOT make this even harder to monitor. DNS has always been a bit of a blind spot for defenders, and this technique exploits that perfectly. Also, yes, prompt injection payloads are now showing up in DNS records too. 🤬

    TL;DR
    ⚠️ Malware stored in DNS TXT records
    🧠 Chunked, hex-encoded, reassembled
    🔐 DOH/DOT encrypt lookup behavior
    🪄 Prompt injection payloads spotted too

    arstechnica.com/security/2025/
    #infosec #dnssecurity #malware #promptinjection #security #privacy #cloud #infosec #cybersecurity

  26. Imagine a cunning cyber gang exploiting forgotten DNS records to hijack trusted domains. Could your cloud service be the next target for Hazy Hawk’s sneaky tactics?

    thedefendopsdiaries.com/hazy-h

    #dnssecurity
    #cyberthreats
    #hazyhawk
    #domainhijacking
    #infosec

  27. 🚨 Running BIND on Red Hat? Leaving DNS recursion enabled could open the door to devastating attacks. Learn how to disable it the right way and lock down your server now. #CyberSecurity #RedHat #DNSSecurity

    pupuweb.com/how-to-disable-dns

  28. Skip the groundhog's guess and get guaranteed DNS reliability! 🛡️ DNSimple offers multi-layered DDoS defense and Anycast DNS across 200,000 managed domains. Secure your online presence with expert DNS protection - no shadow required! #DNSSecurity #ReliableDNS #DNS #DevOps

  29. Skip the groundhog's guess and get guaranteed DNS reliability! 🛡️ DNSimple offers multi-layered DDoS defense and Anycast DNS across 200,000 managed domains. Secure your online presence with expert DNS protection - no shadow required! #DNSSecurity #ReliableDNS #DNS #DevOps

  30. With visibility into 97% of the Internet and billions of analyzed DNS records, DTI brings unprecedented insight into domain-based threats.

    Led by industry veteran @danonsecurity, our team delivers actionable intelligence to protect your organization.

    dti.domaintools.com/

    #DNSsecurity #threatintelligence

  31. With visibility into 97% of the Internet and billions of analyzed DNS records, DTI brings unprecedented insight into domain-based threats.

    Led by industry veteran @danonsecurity, our team delivers actionable intelligence to protect your organization.

    dti.domaintools.com/

    #DNSsecurity #threatintelligence

  32. Just 7 yrs ago, we set out to offer a free, global, #privacy-preserving #DNSsecurity service, including reach into traditionally underserved regions with the dedication of a strong team and generous support of many partners, sponsors, friends, supporters, and donors. Happy Anniversary to the entire Quad9 community!

  33. Just 7 yrs ago, we set out to offer a free, global, #privacy-preserving #DNSsecurity service, including reach into traditionally underserved regions with the dedication of a strong team and generous support of many partners, sponsors, friends, supporters, and donors. Happy Anniversary to the entire Quad9 community!

  34. This #CyberSecurityAwarenessMonth, boost your DNS security knowledge with 10 DNS Best Practices to Keep Your Domain Reputation in Check!

    👉 Start here: spamhaus.org/resource-hub/dns/

    #DNSsecurity isn’t just a nice-to-have - it’s a must-have!

  35. This #CyberSecurityAwarenessMonth, boost your DNS security knowledge with 10 DNS Best Practices to Keep Your Domain Reputation in Check!

    👉 Start here: spamhaus.org/resource-hub/dns/

    #DNSsecurity isn’t just a nice-to-have - it’s a must-have!

  36. 💡"Policy can be a game-changer. It doesn’t just make managing your portfolio smoother and more cost-effective; it can also strengthen security and minimize the scope of compromised accounts, domains and DNS."  

    In this article, Prudence Malinki, Head of Industry Relations at Markmonitor, shares insights on the significance of policy in DNS security, including what you need to consider and its effective management.

    Learn more 👇
    spamhaus.org/resource-hub/dns/

    #BestPractice #Policy #DNSSecurity

  37. 💡"Policy can be a game-changer. It doesn’t just make managing your portfolio smoother and more cost-effective; it can also strengthen security and minimize the scope of compromised accounts, domains and DNS."  

    In this article, Prudence Malinki, Head of Industry Relations at Markmonitor, shares insights on the significance of policy in DNS security, including what you need to consider and its effective management.

    Learn more 👇
    spamhaus.org/resource-hub/dns/

    #BestPractice #Policy #DNSSecurity

  38. What is DNS security and why is it important? 🔐🤔 Our latest article talks about 6 DNS attack types and how you can prevent them. 🙌

    🎯 When malicious actors target your DNS, a successful attack can lead to downtime or a data breach. 😧 So, to mitigate risk you should implement some DNS #security best practices, which include knowing what logs help you monitor for and detect a potential incident.

    Learn about the ins and outs of DNS logging best practices for improved security, correlating DNS log events, and more.💡
    graylog.info/4cK3hfm #DNSsecurity #cybersecurity

  39. What is DNS security and why is it important? 🔐🤔 Our latest article talks about 6 DNS attack types and how you can prevent them. 🙌

    🎯 When malicious actors target your DNS, a successful attack can lead to downtime or a data breach. 😧 So, to mitigate risk you should implement some DNS #security best practices, which include knowing what logs help you monitor for and detect a potential incident.

    Learn about the ins and outs of DNS logging best practices for improved security, correlating DNS log events, and more.💡
    graylog.info/4cK3hfm #DNSsecurity #cybersecurity

  40. did _not_ install MTA-STS today, as it's a mere quick-fix for mail domains that don't have DNSSEC yet. But I did install TLSRPT on my DNSSEC & DANE enabled domains. First (empty, cause everything is fine) reports from Google are coming in 👍

    #DNSSEC #DANE #TLSRPT #DNSsecurity #InternetSecurity

  41. The tool I wrote captures DNS requests by listening to network traffic and displays information about destination IP addresses or target domains sent by the client.

    for more join our discord server

    discord.gg/productionbrain

    #ethicalhacker #python #networksecurity #ethicalhacking #pythonprogrammer #python #dnssecurity