DNS flaw response "not good enough"
Posted on 25 Jul 2008 at 11:29
Systems administrators are not doing enough to protect against a gaping DNS vulnerability, warns Dan Kaminsky.
Kaminsky, the security researcher who first unveiled the security flaw earlier this month, explained that 86% of computers were vulnerable on the day of release, but that just over half had still to protect against the problem by installing software updates.
"Not perfect; not even good enough," says Kaminsky, speaking in a webinar prior to the Black Hat security conference, although he would "take 52 any day of week and twice on Sunday."
Kaminsky discovered the flaw six months before its release, but had kept details quiet while an unprecedented effort involving Microsoft, Sun and Cisco was underway to develop fixes.
The flaw affects the DNS system, which translates web addresses into IP addresses. The flaw can poison DNS records so that users will be redirected to malicious websites, even if they typed the correct address of a legitimate website.
Previous attacks on DNS servers have been documented before, but Kaminsky's approach can speed up attacks and is therefore far more potent.
Author: Matthew Sparkes
advertisement
- Microsoft shows courage at Tech-Ed 09
- PowerPoint and Silverlight: a perfect match?
- Why all the fuss over Windows Explorer?
- Your iPhone has a virus? Well it's your fault
- Motorola pays Lucas for its Droid
- Where are the killer apps for Windows?
- Will you hit the Orange iPhone "unlimited" cap?
- USB 3 first benchmark - it's here, and it's fast
- Why Windows 7 has forced me to worry about security
- How Dixons is (under)selling Windows 7
- The bulletproof Dell that costs an arm and a leg
- Microsoft Office 2010 Technical Preview: Q&A
- Lawnmowers, the TyTN II and one odd insurance request
- There'll never be a bulletproof OS
- How far can we trust apps?
- Five nice touches in Outlook 2010
- Building a better Google
- Beware HP's horrendous printer-driver glitch
- Microsoft debuts free Morro antivirus package
- Getting started with Search Server 2008 Express
advertisement

Printed from www.pcpro.co.uk

