Skip to navigation
   
Davey Winder's Blog

The biggest Internet security hole you never heard of…

By Davey Winder in Editorial

Posted in Blog, Security, Internet on July 9, 2008 at 12:35 pm

Permalink | Author Profile

Over six months ago a penetration tester for a security outfit almost literally stumbled upon a fundamental security issue with the Internet, or to be more precise with the Domain Name System (DNS) that we all rely upon for the damn thing to work properly, that researcher Dan Kaminsky describes it as being such a big problem because the system is doing what it is meant to, what it was designed to, and so the vulnerability will simply be repeated by every vendor involved in the DNS business.

So serious was this design flaw, that Kaminsky says it could give any attacker who exploits it the power to replace any web site with a malicious one, and nobody would be any the wiser.

Which is why he did the decent thing and did not go mouthing off on some ’security blog’ about it before it had been fixed. Instead he went straight to the big boys in the business, Microsoft, Cisco, Juniper etc and asked for them to work together to fix the problem.

I can only say that I am pleased to report they did just that. And this week a number of hardware vendors have simultaneously released patches to seal the DNS security deal. Microsoft, for example, included the fix in its scheduled Patch Tuesday updates.

It is expected that all major ISPs will have applied the necessary ointment to the DNS within 30 days. Which is probably why neither Kaminsky nor the vendors have gone into technical specifics.

If you are truly curious, then the most information currently available can be found at CERT who issued a National Technical Cyber Security Alert on Tuesday.

Meanwhile, Dan the man of the moment Kaminsky has made a browser based DNS exploit checking tool available on his website for any who wants to see if they are still vulnerable or not.

12345
Rated: 100% (2 votes)
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments

Comment by Simon Bisson & Mary Branscombe - July 10, 2008 on 12:21 am

The patch for Windows causes problems for security software like ZoneAlarm, not unexpectedly; I suppose it’s also to be expected that users are criticising Microsoft for the interaction rather than either understanding that it’s a security issue or, if appropriate, criticising the other software vendor…

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

Linux botnet China trust InfoSec HPC Obama remote working Rant tech payment server black hat web museum network USA second life malware library Deal virus hacker SMS Digg broadband Energy Bill Gates Texas Instruments biometrics betting science theft fool Zango Noro survey Funny teleworking worker policy Microsoft Web Development NBC data Mobile Phone BSI carbon copy privacy stupidity avatar hacking open source Yahoo CAPTCHA economics symantec prison Windows transactional security Big Brother debian Supercomputer remote documentation Vista virtual machine statistics books Finjan The Federation Application OCR politics code security work SSL crime computer christmas IP man-in-the-middle xmas staffing stupid ISPA news compromise Health millions computing Russia IDC sick exploit Silverlight Performance computing ID Theft e-commerce help MSN technology scan surveys green payments spam holidays web 2.0 Gartner Windows 7 scam Battery virtual world universe Space Texting Trojan phishing Project Paris Hilton hardware Government office Steve Jobs copyright Flash Blogging banking fraud size linkedin email report ASUS XP home DNS terrorism Rumour Apple Microchip rootkits Adobe OS search graphics service dumb Business Research Eee PC MSNBC global outsourcing Ballmer workplace VPN Jesus Phone fun Hack MiniBook archiving Video chips world of warcraft worm Olympics Lotus students BOFH Top 500 storage scareware Mars Programming Firefox mobile Twitter Kill Switch hypervisor Facebook patch management iPhone money iPhone 3G standards Eee digitise migration Internet gaming environment AMD hubdub Death VM social networking printing FBI productivity adware Software development ecommerce IBM NASA banks MessageLabs Google shopping credit card fraud data protection
Advertisement
Advertisement
Advertisement