ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

New flaws expose Net to attacks

Published: 14 Nov 2002 09:04 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A network protection firm on Tuesday revealed three new flaws in the software on which the Internet's domain name system relies.

All three flaws could lead to denial-of-service attacks on the majority of domain name system (DNS) servers, which act as the address books for the Internet, said Internet Security Systems, which discovered the vulnerabilities. One flaw could allow an attacker to run programs on a vulnerable computer. Given the Internet attacks leveled at the DNS root servers three weeks ago, new attacks could be around the corner, ISS warned.

"A worm could be developed using this thing," said Dan Ingevaldson, leader for ISS's vulnerability research and development group. "We feel this vulnerability is in the same class as" the flaw that led to Code Red.

The flaws occur in the popular Berkeley Internet Name Domain (BIND) software. Servers running versions of the software up to and including 4.9.10-REL and 8.3.3-REL will have to patch the servers. While BIND 9 is the latest version of the software, many administrators still use BIND 8 and many older systems continue to run BIND 4.

ISS's Ingevaldson said that tens of thousands to hundreds of thousands of servers connected to the Internet are running some version of BIND.

While the attacks on the root servers in October didn't exploit any particular flaw, the FBI and System Audit Network Security Institute have warned repeatedly that un-patched software flaws in BIND software were among the top 10 vulnerabilities on the Internet for Unix-like operating systems.

The Internet Software Consortium, which manages the open-source BIND software, recommends that administrators upgrade their servers to BIND 9.2.1.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
93 out of 164 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Want to make a name for yourself in C# Enterprise development?

Despite being a large national company you will be working within a team of 20 and have the great opportunity of standing out from the crowd and ...

Software Development Manager(.Net/Web) - Household name -London(65K+)

Software Development Manager(.Net/Web) My Sports and Media client are a house-hold name, based in Central London. They are seeking a Software ...

ISP Network/Systems Engineer : Linux, Unix, Windows, Cisco CCNA

You will be tasked with supporting more then 200 web hosts running web servers, mail servers, domain name servers, streaming servers. Our client is ...

Discussions

319762 319762

Eve of Distraction

Saturday 26 July 2008, 4:37 AM

1 comment

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal