Advertisement
Promo

Security threats Toolkit

First attacks on DNS flaws reported

David Meyer ZDNet.co.uk

Published: 28 Jul 2008 13:37 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The first attacks that are likely to have stemmed from a serious Domain Name System flaw have been reported.

The existence of the Domain Name System (DNS) flaw, which could be used to redirect browsers to malicious sites, was revealed at the start of July by security researcher Dan Kaminsky. Multiple vendors, including Microsoft and Cisco, have already issued patches to counteract any attacks.

However, code that could act as a blueprint for an attack via the flaw was published on Wednesday by Metasploit, which provides penetration-testing tools. On Friday, a user named James Kosin posted an excerpt from a server log to a Fedora Linux mailing list, claiming it proved attacks based on the DNS flaw had begun.

"The DNS attacks are starting," read Kosin's post. "Below is a snippet of a logwatch from last night. Be sure all DNS servers are updated if at all possible. The spooks are out in full on this security vulnerability in force. This is your last warning... Patch or upgrade now!"

Approached via email to discuss his post, Kosin appeared to retreat from saying the activity he had observed was definitely an attack. "I can't prove or disprove any claim that it is an exploit of the flaw other than to say it started about a week ago," he told ZDNet.co.uk. "I'd already updated the server's DNS application, so I'm taking an educated stab in the peripheral internet here in saying it is a good possibility of being a possible exploit."

Read this

Comment
Comment: The man who transformed internet security

When security researcher Dan Kaminsky discovered a potentially disastrous flaw within the Domain Name System, his measured response led to the biggest-ever multiparty patch release

Read more +

Carl Leonard, a threat research manager for the security company Websense, who reported Kosin's post, said his company had still not seen any attack reports in its own systems. However, he said Websense does "expect to" see such reports. "The exploit code is available and people still need to patch systems," he said. "It's kind of a waiting game at the moment."

The flaw in question is inherent to the DNS — the part of the internet's infrastructure that takes a human-readable web-address request and finds the corresponding numeric IP address. The nodes of the DNS are nameservers and, if one of those is left unpatched, the new attack code could fool the server into redirecting user requests to phishing sites or other malware-hosting sites.

Those who need to apply the patch are mostly internet service providers (ISPs) and companies that run their own nameservers. Users can check if their nameservers are vulnerable through a tool hosted on Kaminsky's blog.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
7 out of 9 people found this useful


Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters