Newsletter:

Skip Navigation LinksHome > News > Security > Kaminsky delivers DNS dirt

Kaminsky delivers DNS dirt

By Shaun Nichols
8 August 2008 12:34PM
Tags: kaminsky | delivers | dns | dirt

Security researcher Dan Kaminsky has delivered his much-anticipated report on the DNS flaw he discovered earlier this year.

Kaminsky explained to a crowd at the Blackhat conference in Las Vegas that the flaw he uncovered could be used for attacks far more complex and sinister than just phishing operations.

The researcher began his presentation with an update on the patching operation. He noted that hundreds of millions of users have been protected through updates by vendors and ISPs, and the majority of Fortune 500 companies had deployed patches for their servers as well

The vulnerability centers around the way the domain name system looks up information linking URLs to IP addresses. In short, the flaw allows an attacker to "poison" a given DNS server and redirect traffic to the malicious site.

The vulnerability has mostly been discussed for its possible use in phishing attacks. However, Kaminsky warned that it could also be used to compromise mail servers, allowing the attacker to intercept and redirect messages.

Kaminsky also admitted that the suggested solution to the problem, randomizing the source port, may not be a permanent solution. He said that the solution is more of a "stopgap" to stave off attacks until a better defense system can be developed.

He also warned that the DNS flaw could be the first of many potentially catastrophic flaws found in coming years, as more commonly used services and systems are probed for fundamental weaknesses.

"Even with DNS fixed, there are other scenarios in which unencrypted IP traffic is lost to an attacker," Kaminsky noted in the presentation.

"The attacker is capable of way more than he should be."

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch





Product Reviews

Star Rating
The Cyber-Ark Enterprise Password Vault, or EPV, is a high-end password management powerhouse.
Star Rating
The Hitachi ID-Archive sets its focus on password randomisation.
Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Star Rating
On the surface, RoboForm Enterprise starts out looking like a single sign-on product, but that is just on the...
Unified Communications Podcast Centre

TopTopics
(6902) -  microsoft
(6474) -  iinet
(6465) -  copyright
(6465) -  afact
(6347) -  internet
(5920) -  servers
(5920) -  mipi
(4078) -  phone
(4076) -  telstra
(3647) -  nvidia
(3329) -  broadband
(3273) -  nbn
(2430) -  avg
(1970) -  onecare
(1885) -  google