ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

'Harmless' DNS data can mask attacks

Published: 02 Aug 2004 09:10 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The same technology that allows Web surfers to locate and connect to computers on the Internet can be used to create covert communications channels, bypass security measures and store distributed content, a security researcher said on Saturday.

The security hack essentially uses data transferred by domain name service (DNS) servers to hide additional information in the network communications. DNS servers act as the white pages of the Internet, invisibly transforming easy-to-remember domain names -- such as www.cnet.com -- into the numerical network addresses used by computers. Moreover, corporate security measures, such as firewalls, tend to ignore DNS data because they assume it's harmless, said Dan Kaminsky, a security researcher for telecommunications firm Avaya and a speaker at the Defcon hacking conference here.

"DNS is everywhere -- you cannot communicate over the global Internet without knowing where to go," he said. "No one notices DNS; no one monitors it."

That flaw in most firms' network security leaves a vulnerability that can be used by hackers to sneak intellectual property outside a company, communicate with a compromised server inside the company, or gain free access to many wireless and Internet services found in coffee houses and hotels, he said.

Covert channels are a common area of research for security experts and hackers. Last year, another security expert demonstrated a way to send dribs and drabs of data across the Internet by hiding them in network packets. The concept goes back at least 15 years, but the Avaya security researcher has actually created useful tools for people who want to send covert messages over DNS.

At Defcon, Kaminsky showed off server software that acts as a communications hub for covert messages and a program that can insert data into DNS requests. Using the software, he could send instant messages over an encrypted communications channel carried by spoofed DNS requests. He also showed off broadcasting streaming radio over the covert channel.

The data will not normally be recorded or detected by network security, Kaminsky said, because it appears to just be legitimate DNS servers communicating with one another.

"The user is not actually sending data outside the network," he said. "They (seem to be) requesting data from the local DNS server and it is sending it outside the network."

There are other security side effects to network administrators not paying attention to DNS packets. Online services that allow a user to connect to the Internet after logging into a captive portal -- such a system allows wireless users to get on the Internet at Starbucks -- allow DNS packets to pass through the security. That means that a hacker could use Kaminsky's software to get free wireless access on most such networks.

Network administrators should pay more attention to DNS, said Kaminsky. Servers infected with the MSBlast worm, for example, used the service to lookup the address of Microsoft's windowsupdate.com server, and that made DNS a good method for detecting compromised computers.

"We have known that this is feasible for years," he said. "It's time to pay attention."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
84 out of 129 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Partner Alliances Director

To define and develop regional Partner channels to market. Sales Director - To Define the Partner channel sales strategy. Achieving the annual ...

JAVA, SML / XSLT, JSP, HTML, Javascript DEVELOPER 40,000 London

In the role you will be responsible for developing new server based applications to meet with Product requirements, enhancing and maintaining the ...

Service Co-ordinator

Main Activities and tasks: - Manage requests through liaison with customers and provide single point ownership for multi-domain calls. The scheduling ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation