Advertisement
Promo

Online business Toolkit

Security firm RSA falls foul to DNS hack

Will Knight ZDNet.co.uk

Published: 14 Feb 2000 17:19 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Computer security firm RSA has had one of its Web sites effectively defaced by computer criminals apparently keen to make a point about the insecurity of DNS (Domain Name System) authentication. The affected site is an older RSA site, not its primary home page.

According to security and encryption expert Brian Galdman, the culprits appear to have gained access to a high-level DNS server, rather than broken into the server that hold the page itself.

This latest high profile attack adds to the argument that, as illustrated by the recent spate of distributed DoS (distributed denial of service) attacks, there remain major security issues -- even for the best-equipped Web sites.

By noon on Monday, http://www.rsa.com led to a defaced page with a virtually incoherent message. However, the server on which the Web site exists hasn't been hacked: the domain name simply points to another IP address. A spokesman for RSA says that http://www.rsa.com is RSA Security's old Web site, which is maintained as "a pointer" to the official Web site at http://www.rsasecurity.com.

Although hacks on DNS servers aren't unknown, Gladman claims the problem points to more serious issues with the Internet's infrastructure. He believes that if these malicious computer hackers have access to enough DNS servers, they could, in theory at least, "take down the whole Internet".

The target is probably no coincidence, says Gladman. He explains that attacking a firm specialising in encryption may illustrate dissatisfaction with the US government for restricting access to strong encryption. "This shows the extreme folly of the US government, in particular, in preventing technology that would prevent this sort of attack being deployed. They're making the point that they're not secure. Hopefully, someone will start asking why they're not."

The RSA site has now been pulled down. A spokesman from the company reckons it will be around 24 hours before it goes live again.

Several groups have proposed a more secure form of DNS, but none have yet been implemented. For example, RFC 2137, first proposed in April 1997, outlines a method to use digital signatures to ensure that only authorised persons can update a DNS record.

What do you think? Tell the Mailroom.

For full coverage see the Denial of Service Roundup.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
84 out of 118 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters