First DNS attacks reported

 

The first attacks to on the Kaminsky DNS vulnerability have been reported.

The attack was reported by a user named James Kosin to a Fedora Linux mailing list.

Kosin posted a log which he said was gathered Thursday night. The attacker attempts to access the server's cache for entries to such sites as myspace, ebay and Wachovia.

The attack attempts to target a vulnerability in the Domain Name System in which an attacker could alter the cache on a DNS server to redirect site requests to malicious third-party sites.

"The spooks are out in full on this security vulnerability in force. Patch or upgrade now!" wrote Kosin.

Industry experts, including Kaminsky himself, have issued similar warnings to administrators. Kaminsky intentionally held off on releasing the details of the flaw until vendors could patch it.

Exploit code for the vulnerability was posted earlier this week as a module for the Metasploit framework.

Though experts estimate that most major ISPs and vendors have patched the flaw, poorly-maintained DNS servers could still be open to the attack.

Copyright ©v3.co.uk


First DNS attacks reported
 
 
 
 
 
Top Stories
The New Zealand telco problem
Opinion: Could Telstra save Kiwi telcos?
 
IT price probe to 'name and shame' gougers
Industry ducking the issue, committee claims.
 
Revealed: 2012 e-government award winners
Government highlights projects, professionals of the year.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Should the Government enact new legislation to protect copyright holders in the digital age?

   |   View results
Yes
  19%
 
No
  81%
TOTAL VOTES: 471

Vote