ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

New flaws expose Net to attacks

Published: 14 Nov 2002 09:04 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A network protection firm on Tuesday revealed three new flaws in the software on which the Internet's domain name system relies.

All three flaws could lead to denial-of-service attacks on the majority of domain name system (DNS) servers, which act as the address books for the Internet, said Internet Security Systems, which discovered the vulnerabilities. One flaw could allow an attacker to run programs on a vulnerable computer. Given the Internet attacks leveled at the DNS root servers three weeks ago, new attacks could be around the corner, ISS warned.

"A worm could be developed using this thing," said Dan Ingevaldson, leader for ISS's vulnerability research and development group. "We feel this vulnerability is in the same class as" the flaw that led to Code Red.

The flaws occur in the popular Berkeley Internet Name Domain (BIND) software. Servers running versions of the software up to and including 4.9.10-REL and 8.3.3-REL will have to patch the servers. While BIND 9 is the latest version of the software, many administrators still use BIND 8 and many older systems continue to run BIND 4.

ISS's Ingevaldson said that tens of thousands to hundreds of thousands of servers connected to the Internet are running some version of BIND.

While the attacks on the root servers in October didn't exploit any particular flaw, the FBI and System Audit Network Security Institute have warned repeatedly that un-patched software flaws in BIND software were among the top 10 vulnerabilities on the Internet for Unix-like operating systems.

The Internet Software Consortium, which manages the open-source BIND software, recommends that administrators upgrade their servers to BIND 9.2.1.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
93 out of 164 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

SAS Developer - Urgently Needed - Massive name in Utilities

A massive name in the financial and insurance industry based in Hampshire has an urgent requirement for a SAS developer to join to participate in the ...

Cognos Planning Analyst - Major Household Name - Bedfordshire - Urgent

Cognos Planning/Enterprise Planning/EP Senior Consultant required for a Bedfordshire-based household name who is currently undergoing rapid ...

Integration Engineer

Work closely with Sky's chosen integration partners to add domain expertise and product knowledge whilst assuring alignment to departmental visions ...

Discussions

0xyGen 0xyGen

Please help me in choosing web hosting

Sunday 20 July 2008, 10:32 AM

1 post
1000030281 1000030281

Facebook Bans Firefox 3

Sunday 20 July 2008, 2:33 AM

1 comment

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal