ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Security firm RSA falls foul to DNS hack

Will Knight ZDNet.co.uk

Published: 14 Feb 2000 17:19 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Computer security firm RSA has had one of its Web sites effectively defaced by computer criminals apparently keen to make a point about the insecurity of DNS (Domain Name System) authentication. The affected site is an older RSA site, not its primary home page.

According to security and encryption expert Brian Galdman, the culprits appear to have gained access to a high-level DNS server, rather than broken into the server that hold the page itself.

This latest high profile attack adds to the argument that, as illustrated by the recent spate of distributed DoS (distributed denial of service) attacks, there remain major security issues -- even for the best-equipped Web sites.

By noon on Monday, http://www.rsa.com led to a defaced page with a virtually incoherent message. However, the server on which the Web site exists hasn't been hacked: the domain name simply points to another IP address. A spokesman for RSA says that http://www.rsa.com is RSA Security's old Web site, which is maintained as "a pointer" to the official Web site at http://www.rsasecurity.com.

Although hacks on DNS servers aren't unknown, Gladman claims the problem points to more serious issues with the Internet's infrastructure. He believes that if these malicious computer hackers have access to enough DNS servers, they could, in theory at least, "take down the whole Internet".

The target is probably no coincidence, says Gladman. He explains that attacking a firm specialising in encryption may illustrate dissatisfaction with the US government for restricting access to strong encryption. "This shows the extreme folly of the US government, in particular, in preventing technology that would prevent this sort of attack being deployed. They're making the point that they're not secure. Hopefully, someone will start asking why they're not."

The RSA site has now been pulled down. A spokesman from the company reckons it will be around 24 hours before it goes live again.

Several groups have proposed a more secure form of DNS, but none have yet been implemented. For example, RFC 2137, first proposed in April 1997, outlines a method to use digital signatures to ensure that only authorised persons can update a DNS record.

What do you think? Tell the Mailroom.

For full coverage see the Denial of Service Roundup.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
74 out of 107 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS,

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS, - Lambeth - 2198 RM helps to push the boundaries of technology to ...

Junior Level Systems Admin(desktop,server,AD,DNS,DBA) BANKING

DNS, DHCP, TCP/IP & Database administration for Sybase, Oracle or MS SQL Servers. A market leading developer of trading & risk management systems ...

Operations Engineer - Server2003/SAN/NetBackups/WINS/DNS/LDAP/London

Operations Engineer / Media/ Server2003/ SAN/ NetBackups/ WINS/ DNS/ LDAP/ London/ 60k My client is a market leading global Media Organisation ...

Sentry Posts Blog

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment

Trades Unions against ID Cards

The Trades Union Congress (TUC) has backed up airport workers protesting against ID cards, the Financial Times reports. In a letter to Home Secretary Jacqui Smith, the TUC said it... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains