WHIR | BLOGS | WEB HOST NEWS | FIND WEB HOSTS | RESELLER HOSTING | MAGAZINE | WHIR TV | NEWSLETTER | rss feeds
web hosting news - daily web host interviews, insight Jobs | Events | Sitemap | Search
Green Data Center Info


WEB HOSTING NEWS | BLOGS | INTERVIEWS | EUROPE | EVENTS | WEB HOSTING JOBS

<< MSN Uses dotMobi Mobile Database     VeriSign Reports Q2 Losses >>


Kaminsky Explains DNS Attacks

By David Hamilton, theWHIR.com

August 7, 2008 -- (WEB HOST INDUSTRY REVIEW) -- IOActive (ioactive.com) director of penetration testing Dan Kaminsky has publicly commented on a domain name service flaw he discovered July that makes just about everything on the Internet vulnerable because most online actions involve a DNS request.

   
Level 1 PCI DSS Certified Service Provider! DataPipe delivers the best network & support; top tier data centers; New York metro, Silicon Valley, London, Hong Kong, Shanghai. DataPipe - Personal Touch, Global Reach.

While technical details were leaked in late July, Kaminsky addressed a packed audience at Black Hat 2008 in Las Vegas to explain why hackers exploit this DNS weakness.

According to reports from Cnet News (news.cnet.com), Kaminsky said security analysts had previously considered it too difficult to infect DNS records. The process is like a race between a good guy and bad guy vying for a secret number transaction ID. "You can get there first," he told Cnet, "but you can't cross finish line unless you have the secret number."

Before the patch, he said, the bad guy had a 1 in 65,000 chance of winning the race because the ID is based partly on the port number used; now, with the patch, chances are lowered to 1 in more than two billion.
 
Kaminsky said that hackers have much to gain from exploiting DNS, which is deeply embedded in our lives according to Cnet. There are three distinct periods of computer hacking Kaminsky said. The first was attacking servers like FTP and Telnet; the second was browsers including Javascript and ActiveX; the third age is about to begin, where attacking everything will be possible.

Kaminsky has been urging IT workers to implement patches to protect this potentially dangerous loophole, noting that only roughly 85 percent of Fortune 500 companies have patched their networks, almost a month after the flaw was initially found.

Print this Page       Email this Page        Add to: | del.icio.us | digg



Q&A: Paul Hirsch, AIHSP

Q9 Moves Forward Amid Acquisition

Mailtrust Blooms Under Rackspace

Q&A: Tucows Marketing VP Ken Schafer

Q&A: Maria Farnon, Level 3 VP

Outsourced, Not Offshore in Mexico

Q&A: Mosso Uptime Chief Bruce Runyan

More feature interviews and reports
 

Asymmetry of Information

Applications and the law

Rackspace to Review Results

Interview Notes: Patrick Matthews and Kirk Averett of Mailtrust

TrendPoint's Four-Point "Green Data Center" Plan

Video Interview with Dan Ushman, SingleHop

More posts from our Bloggers


Major Internet Outages

Weta Digital Builds NZ Facility

DataChambers Expands NC Facility

Web Traffic Grows 53%, Capacity More

Replace 3 Year Servers, says Memset

Gomez Adds Testing For Chrome, IE 8

Internap Delivers CDN for Round Table

The Web Host Industry Week in Review

Comcast Appeals FCC Ruling

IRS Taxed By Unauthorized Servers

Server Intellect Debuts MS SQL 08

Secure64 Gains $3.7M In Funding


 

 

SPONSORED LINKS
> Apollo Hosting: Award Winning Website Hosting from $6.96 – Click Here!

> iWeb: Quality servers. 3000GB of traffic for only $69

> TopLayer: SC Mag Recommended. Protect against DDoS Attacks & more.

> Parallels: Automation and Virtualization. Buy ONLINE or Learn MORE!

> Website Source: Powerful Website hosting starting at $6.85

> Rackspace: Hosting Solutions Built to Your Needs

> GeoTrust: The Most Flexible SSL Partner Program

> The Planet: Dedicated servers and managed hosting solutions

> Sell More Services with Microsoft Services Provider Licensing!

> SERVER4YOU: Dedicated servers – starting $29!

WHIR NEWSLETTER SIGN-UP | MANAGE SUBSCRIPTIONS | WHIR RSS FEEDS
Name:
Email:
Password:
theWHIR Blog Email Update
Magazine
Daily News
Find Web Hosts
Occupation:
Company Type:

Find Web Hosts | Reseller Hosting | Personal Web Hosting | Small Business Web Hosting | Dedicated Servers | Managed Hosting | Adult Web Hosting


About WHIR | Online Advertising | Print Advertising | Print Subscription | Email Newsletters | RSS Feeds
 
Submit News | Privacy Policy | Buy Reprints

Web Host Industry Review, Inc. is not responsible for the content of comments submitted by our users.

  © Copyright Web Host Industry Review, Inc.