Apple has failed to fully patch a DNS vulnerability, say researchers
R E L A T E D   C O N T E N T
ADVERTISEMENT

Apple misses mark on DNS patch

Leopard remains vulnerable to cache poisoning, say researchers

Shaun Nichols in San Francisco, vnunet.com 05 Aug 2008
ADVERTISEMENT

Security researchers are claiming that Apple has failed to fully patch the high profile DNS cache poisoning error.

The company issued the patch last week as part of a larger security update. The so-called Kaminsky flaw (named after its discoverer, Dan Kaminsky) has sent vendors scrambling to patch what is said to be a fundamental vulnerability in the DNS system.

According to Andrew Storms, director of security operations for network security firm nCircle, Apple's patch doesn't quite do the job. Storms found that the update doesn't force source port randomisation for client libraries, an essential fix for preventing the spooking attack.

Storms said that while the server component of the error is fixed, client machines remain vulnerable.

"For Apple, it matters most that they patch the client libraries since there are so few OSX recursive servers in use," he noted.

"The bottom line is that despite this update, it appears that the client libraries still aren't patched."

Storms was not the only person to note Apple's oversight. Sans researcher Swa Frantzen also noticed the flaw. Frantzen pointed out that a fully patched Leopard system still uses incrementing ports, making port selection predictable and allowing an attacker to still perform the cache-poisoning exploit.

"So Apple might have fixed some of the more important parts for servers, but is far from done yet as all the clients linked against a DNS client library still need to get the workaround for the protocol weakness," said Frantzen.

See also:

FirefoxFlaws patched for versions 2 and 3  18 Jul 2008
MicrosoftRedmond takes second crack at Bluetooth flaw  21 Jun 2008
Trojan horseMalware spotted in the wild  21 Jun 2008
Safari for Windows3.1.2 update addresses four security vulnerabilities  20 Jun 2008

All Bugs & Fixes
Tags: Apple, Dns, Kaminsky, Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| JAM Recruitment
Software Test Engineer 6 Weeks Contract £ 35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements ... more >
| JAM Recruitment
Software Test Engineer 3 Months Contract £35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements based ... more >
| Aston Carter
Major Investment Bank requires a Business Analyst to work within reference data IT. The reference data IT function is responsible for the three internal systems. One of the systems is a strategic repository for Client ... more >
| JAM Recruitment
Job Ref: CY - 27021979 Package: £25 – 42,000 +Bens Location: YORKSHIRE Job type: Occupational Health Position type: Permanent Hours: Full time Contact name: Mr Colin Youle Contact Company: JAM HUMAN RESOURCES Are you a ... more >
More job opportunities