ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Synchronised, multi-vendor DNS patches released

Robert Vamosi CNET News.com

Published: 09 Jul 2008 08:21 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A security researcher has responsibly disclosed a fundamental flaw within the Domain Name System, or DNS, the addressing scheme behind the common names used on the internet.

Currently, it may be possible to guess these transaction ID values in advance and assert a malicious server as the authoritative DNS server for a popular bank or e-commerce site. The news was announced on Tuesday.

Dan Kaminsky, director of penetration testing services for IOActive, found the DNS flaw earlier this year. Rather than sell the vulnerability, as some researchers have done, Kaminsky decided instead to gather the affected parties and discuss it with them first. Without disclosing any technical details, he said: "The severity is shown by the number of people who've gotten onboard with this patch."

He declined to name the flaw as that would give away details.

On 31 March, Kaminsky said 16 researchers gathered at Microsoft to see whether they understood what was going on, as well as what would be a fix to affect the greatest number of people worldwide, and when they would issue this fix.

To address the flaw, Kaminsky said the researchers all decided to conduct a synchronised, multi-vendor release. As part of that, Microsoft in its July 'Patch Tuesday' released MS08-037. Cisco rolled out a patch later on Tuesday.

The co-ordinated release covers a wide variety of vendors. Art Manion of US-CERT (United States Computer Emergency Readiness Team) said vendors with DNS servers have been contacted, and there's a longer list of additional vendors that have DNS clients. That list includes AT&T, Akamai, Juniper Networks, Netgear, Nortel, and ZyXEL. Not all of the DNS client vendors have announced patches or updates. Manion also confirmed that other nations with CERTs have also been informed of this vulnerability.

Most systems will be patched automatically. However, those that are not will have 30 days to be patched manually before additional details are made public.

This issue also affects internet service providers (ISPs) used by home users. In the coming days, ISPs are expected to apply the patch to their systems. Hardware routers used by home users should not be affected.

Kaminsky said he will release details in time for Black Hat 2008, on 7-8 August in Las Vegas. However, Microsoft in its security bulletin said its patch uses highly random DNS transaction IDs, random sockets for UDP (User Datagram Protocol) queries, and updates the logic used to manage the DNS cache."

Kaminsky did confirm that the patches released on Tuesday would increase DNS randomness: "Where we had 16-bit before, we now have 32-bit."

To check to see if your system is vulnerable, Kaminsky has provided a DNS checker.

Credit: Massive, coordinated DNS patch released from CNET News.com

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
3 out of 3 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

3 comments

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

5 comments