R E L A T E D   C O N T E N T
ADVERTISEMENT

Kaminsky delivers DNS dirt

Researcher explains risks behind flaw

Shaun Nichols in San Francisco, vnunet.com 07 Aug 2008
ADVERTISEMENT

Security researcher Dan Kaminsky has delivered his much-anticipated report on the DNS flaw he discovered earlier this year.

Kaminsky explained to a crowd at the Blackhat conference in Las Vegas that the flaw he uncovered could be used for attacks far more complex and sinister than just phishing operations.

The researcher began his presentation with an update on the patching operation. He noted that hundreds of millions of users have been protected through updates by vendors and ISPs and the majority of Fortune 500 companies had deployed patches for their servers as well.

The vulnerability centres around the way the domain name system looks up information linking URLs to IP addresses. In short, the flaw allows an attacker to 'poison' a given DNS server and redirect traffic to the malicious site.

The vulnerability has mostly been discussed for its possible use in phishing attacks. However, Kaminsky warned that it could also be used to compromise mail servers, allowing the attacker to intercept and redirect messages.

Kaminsky also admitted that the suggested solution to the problem, randomising the source port, may not be a permanent solution. He said that the solution is more of a "stopgap" to stave off attacks until a better defence system can be developed.

He also warned that the DNS flaw could be the first of many potentially catastrophic flaws found in coming years, as more commonly used services and systems are probed for fundamental weaknesses.

"Even with DNS fixed, there are other scenarios in which unencrypted IP traffic is lost to an attacker," Kaminsky noted in the presentation.

"The attacker is capable of way more than he should be."

See also:

Leopard remains vulnerable to cache poisoning, say researchers  05 Aug 2008
HackerCache poisoning workarounds published  31 Jul 2008
Local ISP attack affects BreakingPoint  31 Jul 2008
HackerFirst attack tool created for vulnerability  25 Jul 2008

All Hacking
Tags: Kaminsky, Dns, Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
United Kingdom | Nottingham University NHS
Analyst/Developer - Nottingham University NHS - £24,103 - £32,653   An analyst/developer is required within the Systems Development Section of Nottingham University Hospitals ICT Services. The successful applicants will be part of a team whose ... more >
Reading, Berkshire, United Kingdom | EDS
Position # 397874 IP Network Administrator Location - Reading Job Description: There is a requirement for an IP network administrator to join the Infrastructure Services operational support team to manage the movement of network resources, ... more >
London, United Kingdom | Royal Borough of Kensington and Chelsea
Web Content Manager - c.£40,000 plus bonus - London   As one of the country's best-performing councils, we're always looking for new ways to improve on excellence. Providing an innovative, high-quality internet site for our ... more >
Reading, Berkshire, United Kingdom | EDS
Job Description: A skilled System Integrator to integrate application hosting environments to support business requirements. The Candidate will possess specific experience of enterprise systems, component validation and integrating technical Infrastructures and system management facilities within ... more >
More job opportunities