ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/registration.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Timeline: Kaminsky’s DNS vulnerability

Is the internet fatally flawed? IT PRO looks at how isolated attacks on Domain Name System servers have risen in profile to become one of the most talked about threats in 2008.

By Asavin Wattanajantra, 18 Aug 2008 at 14:53

A vulnerability affecting the internet Domain Name System (DNS) discovered by Dan Kaminsky became the most high profile security threat of 2008.

He saw that there was a fatal flaw affecting the DNS - which translates web addresses to IP addresses. Users could be sent to malicious sites even if they typed in legitimate addresses and the potential for system-wide problems resulted in an unprecedented multi-vendor effort to create patches for the problem.

But DNS attacks are nothing new. The DNS looks to have problems which still haven't been fully solved, and we trace how the issue has progressed from isolated attacks to the story dominating security for the past couple of months.

February 2007: Hackers take aim at internet root servers

An attack was made on the DNS servers of three of the 13 computers that manage traffic on the internet in a 12-hour Denial of Service (DoS) attack. It was thought to be the one of the biggest seen in four years.

April 2007: New bug hits Windows DNS service

Vulnerability found in the Windows 2003 server which could allow hackers to take over servers and run remote code.

November 2007: DNS servers still vulnerable

A study claims that although DNS servers are increasing and modernising, they are still vulnerable to attacks.

July 2008: DNS protection not good enough

Dan Kaminsky claims that researchers are not providing enough protection for the DNS security hole which he discovered. Kaminsky’s approach was different in that the fact it could speed up attacks and was more potent than seen previously. Kaminsky kept quiet about the flaw for six months, allowing a multi-vendor patch effort involving Microsoft, Sun and Cisco.

July 2008: DNS attacks 'imminent' warns Microsoft

Microsoft warns that the publication of exploit code has increased the chance of attack.

August 2008: Apple’s patch fails to fully protect against DNS flaw

Apple’s belated attempt to create a patch for the DNS system problem does not completely solve the problem, say experts.

Email to a friend

Print this page

Social Bookmark this article: What is this?

Be the first to comment on this article

You need to Login or Register to comment.

advertisement
advertisement

    Latest News Videos in Security

    White papers

Want more background on today's hottest IT trends?

Visit IT PRO's white paper library for more on virtualisation, encryption and other topics.

    Register for IT PRO

You'll get exclusive member benefits including free white papers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Advertisement