WHIR | BLOGS | WEB HOST NEWS | FIND WEB HOSTS | RESELLER HOSTING | MAGAZINE | WHIR TV | NEWSLETTER | rss feeds
web hosting news - daily web host interviews, insight Jobs | Events | Sitemap | Search
Green Data Center Info


WEB HOSTING NEWS | BLOGS | INTERVIEWS | EUROPE | EVENTS | WEB HOSTING JOBS

<< QuickTransit To Run With Hyper-V     Dotser Offers Application Vault >>


DNS Loophole Details Leaked

By David Hamilton, theWHIR.com

July 25, 2008 -- (WEB HOST INDUSTRY REVIEW) -- IOActive (ioactive.com) director of penetration testing Dan Kaminsky advises immediate patching following the accidental leak of specific technical details of a domain name service flaw he discovered earlier in the month, eWeek reports.

   
DataPipe’s high-value managed global IT services help thousands of businesses decrease CAPEX, OPEX, & risk while increasing overall service levels. Partner with DataPipe – Improve your ROI - Extend your IT resources

The details were posted on a well-read blog July 21 despite Kaminsky's plans to keeping the specifics of his discovery secret until the Black Hat conference in August. A hacker can use a DNS attack to redirect page requests to phishing sites or other malicious pages

Hacking community Computer Academic Underground released "Kaminsky DNS Cache Poisoning Flaw Exploit" that credited Kaminsky with discovering "this exploit [which] targets a fairly ubiquitous flaw in DNS implementations which allow the insertion of malicious DNS records into the cache of the target nameserver," according to the documentation. It goes on to publish code with which to exploit this flaw.

CAU released "Kaminsky DNS Cache Poisoning Flaw Exploit for Domains" this week, which expands on the previous exploit. It describes how the DNS insertion completely replaces the original nameserver records for the target domain.

Ernst & Young senior security advisor Nathan McFeters blogged this week that the most significant development was that the hacker will gain "control over an entire domain, whereas the original hijacked an individual host."

Kaminsky has been urging IT workers to implement patches to protect this potentially dangerous loophole. In a Black Hat webcast, Kaminsky said within the first days after the patch was released, "86 percent of people testing their DNS servers were vulnerable. As of the last couple days, there is now 52 percent of DNS servers being tested that are still vulnerable."

Microsoft (microsoft.com) released a security patch earlier in the month to deal with the security vulnerability, that has since needed some modifications by security vendors such as Check Point Software (checkpoint.com) that issued a fix for its ZoneAlarm personal firewall that revives Internet connections affected by patch number KB951748.

Print this Page       Email this Page        Add to: | del.icio.us | digg


COMMENTS

Be the first one to comment on this article. Click the link below to post your comment.

[POST COMMENT]



Q&A: James Bond, Apptix

Noise Filter: McColo Taken Down

Wowza Offers Friction Free Flash

Sun Battles for Greenest Data Center

Concentric Looks to the Clouds

Good Signs in Financial Market Chaos

Salesforce Launches Force.com Sites

More feature interviews and reports
 

What Exactly is Semi-Dedicated Hosting?

Own your own jet

MLB.com switches to Flash; Hosting and Video Streaming Questions

I Was Right - Yahoo Was Stupid

Video Interview with Joey Widener, AT&T

Happy Birthday DMCA

More posts from our Bloggers


DataSite Offers Green Facility Stats

Google Hosts Life Mag Image Archive

Level 3 CDN Backs Pando Cloud

HMS Adds Managed Services Webpage

NetFirms Hosts Pixlr Image Editor

Hosting Sales and Promos Roundup

Verio Offers Email Compliance Service

The Web Host Industry Week in Review

IBM Tests IDC Heating Homes

CRTC Approves BCE Traffic Shaping

ServerBeach Hosts Photo Site Natuba

DataPipe: A Top Growing NJ Firm


 

Sales Operator

Management Trainer

Senior Account Manager, Dedicated Hosting

Sales Executive

Senior Accounting Analyst

Technical Solutions Engineer

Product Manager

Account Manager

Ajax Experienced Developer

International Accounting Manager

 

SPONSORED LINKS
> Apollo Hosting: Award Winning Website Hosting from $6.96 – Click Here!

> iWeb: Quality servers. 3000GB of traffic for only $69

> TopLayer: SC Mag Recommended. Protect against DDoS Attacks & more.

> Parallels: Automation and Virtualization. Buy ONLINE or Learn MORE!

> Website Source: Powerful Website hosting starting at $6.85

> Rackspace: What Do You Get With Your Hosting Provider?

> Verio: Get Email Anywhere w/ Hosted Exchange $11.95/mo, 2 Mo Free

> Mosso: Leverage the Rackspace Cloud. 30 day risk-free trial. Click here to learn more.

> IronScale: Why Rack? Automate with IronScale Managed Hosting

> Is your company hiring? Post your job listing here!

WHIR NEWSLETTER SIGN-UP | MANAGE SUBSCRIPTIONS | WHIR RSS FEEDS
Name:
Email:
Password:
theWHIR Blog Email Update
Magazine
Daily News
Find Web Hosts
Occupation:
Company Type:

Find Web Hosts | Reseller Hosting | Personal Web Hosting | Small Business Web Hosting | Dedicated Servers | Managed Hosting | Adult Web Hosting


About WHIR | Online Advertising | Print Advertising | Print Subscription | Email Newsletters | RSS Feeds
 
Submit News | Privacy Policy | Buy Reprints

Web Host Industry Review, Inc. is not responsible for the content of comments submitted by our users.

  © Copyright Web Host Industry Review, Inc.