Enjoy unlimited access to all forum features for FREE! Optional upgrade available for extra perks.
Domain summit 2024

Major DNS Flaw Revealed - Could Cause DNS Server & Domain Hijacking

Status
Not open for further replies.

radioz

Level 8
Legacy Platinum Member
Joined
Apr 14, 2003
Messages
1,136
Reaction score
18
Feedback: 167 / 0 / 0
Hi I just read this on Google News:

One day after a security company accidentally posted details of a serious flaw in the Internet's Domain Name System (DNS), hackers are saying that software that exploits this flaw is sure to pop up soon.

Several hackers are almost certainly already developing attack code for the bug, and it will most likely crop up within the next few days, said Dave Aitel, chief technology officer at security vendor Immunity. His company will eventually develop sample code for its Canvas security testing software too, a task he expects to take about a day, given the simplicity of the attack. "It's not that hard," he said. "You're not looking at a DNA-cracking effort."

The author of one widely used hacking tool said he expected to have an exploit by the end of the day Tuesday. In a telephone interview, HD Moore, author of the Metasploit penetration testing software, agreed with Aitel that the attack code was not going to be difficult to write.

The flaw, a variation on what's known as a cache poisoning attack, was announced on July 8 by IOActive researcher Dan Kaminsky, who planned to disclose full details of the bug during an Aug. 6 presentation at the Black Hat conference.

That plan was thwarted Monday, when someone at Matasano accidentally posted details of the flaw ahead of schedule. Matasano quickly removed the post and apologized for its mistake, but it was too late. Details of the flaw soon spread around the Internet.

Full story link from PC World Magazine: http://www.pcworld.com/businesscenter/article/148784/with_dns_flaw_now_public_attack_code_imminent.html

Other takes on the issue:

Wired Magazine - http://blog.wired.com/27bstroke6/2008/07/details-of-dns.html


Channel Web - http://www.crn.com/security/209400660

Earlier sory (before leak) - http://www.techworld.com/security/news/index.cfm?newsid=102110&pn=1
 

radioz

Level 8
Legacy Platinum Member
Joined
Apr 14, 2003
Messages
1,136
Reaction score
18
Feedback: 167 / 0 / 0
The new news is that the details of the flaw were unintentionally released to the public today!
 

Eraser

Level 4
Legacy Platinum Member
Joined
May 12, 2007
Messages
197
Reaction score
1
Feedback: 5 / 0 / 0
unintentionally??????????

I don't think so.
 
Status
Not open for further replies.

The Rule #1

Do not insult any other member. Be polite and do business. Thank you!

Sedo - it.com Premiums

IT.com

Premium Members

AucDom
UKBackorder
Be a Squirrel
MariaBuy

New Threads

Our Mods' Businesses

UrlPick.com
URL Shortener

*the exceptional businesses of our esteemed moderators

Top Bottom