Hacker
The DNS flaw allows hackers to reroute information sent across the internet
R E L A T E D   C O N T E N T
ADVERTISEMENT

DNS flaw causes security scramble

Cache poisoning workarounds published

Clement James, vnunet.com 31 Jul 2008
ADVERTISEMENT

The well-publicised vulnerability in the DNS system, which can lead to DNS cache poisoning, has got security firms scrambling to provide protection.

Security service provider Integralis introduced a three-point system this week which it claims provides an immediate fix to eliminate the security risks and provide long-term protection.

The vulnerability allows a hacker to reroute information sent across the internet in such a way that existing security software and appliances may not detect a problem.

Once the routing has been changed the hackers can then extract any information transmitted. This can enable identity theft and major criminal activity on a personal and business basis.

DNS cache poisoning allows an attacker to introduce 'fake' DNS information into a caching name server.

Once 'poisoned' the DNS routing is changed to take legitimate URL requests and send them to a 'rogue' server which looks and acts like the actual server.

"Email and browser-based 'in the cloud' applications play a major part in day-to-day business transactions, so a security breach of this kind could have catastrophic business and personal implications," said Graham Jones, UK managing director at Integralis.

"Identity theft and business espionage are immediate threats, and stolen competitive information could be sold to the highest bidder."

Integralis explained that the quickest way to stop the security breach is to install a product that will use the root DNS servers and only trust authoritative name servers, thereby addressing the vulnerability for all email and internet traffic.

The second step is to work directly with security vendors to supply details of software patches available to close the security vulnerability.

Finally, an assessment of current security protection should be performed to help an organisation gain a good understanding of the information security issues it may have.

See also:

Local ISP attack affects BreakingPoint  31 Jul 2008
Professor John WalkerDNS slip-up opens up CIA, FBI and DoD information  28 Jul 2008
HackerFirst attack tool created for vulnerability  25 Jul 2008
SecurityExperts sound alarms over early disclosure  23 Jul 2008

All Hacking
Tags: Dns, Security, Software, Strategy

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| JAM Recruitment
Software Test Engineer 6 Weeks Contract £ 35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements ... more >
| JAM Recruitment
Software Test Engineer 3 Months Contract £35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements based ... more >
| Aston Carter
Major Investment Bank requires a Business Analyst to work within reference data IT. The reference data IT function is responsible for the three internal systems. One of the systems is a strategic repository for Client ... more >
| JAM Recruitment
Job Ref: CY - 27021979 Package: £25 – 42,000 +Bens Location: YORKSHIRE Job type: Occupational Health Position type: Permanent Hours: Full time Contact name: Mr Colin Youle Contact Company: JAM HUMAN RESOURCES Are you a ... more >
More job opportunities