ANTenna Blog -- Security

Poisoned DNS Woes Grow

Posted by Keith Ferrell Friday, Aug 22, 2008, 05:02 PM ET

It's been weeks since Dan Kaminsky revealed that the Domain Name System (DNS) that underlies the Internet's address routing system was dangerously flawed. It's been a slightly shorter time since patches were released, and yet unpatched DNS vulnerabilities still exist and are beginning to be exploited. Why aren't we surprised?

The latest example of a poisoned DNS cache -- an exploit that can direct browsers to malicious Web sites -- involves a DNS server on one of China's largest Internet Service Providers (ISP.)

The exploit on the evidently unpatched China Netcom DNS server takes advantage of misstyped domain names: ISP customers who strike a wrong character risk being redirected to a malicious Web site.

There are plenty of other indications that a storm of DNS exploits and exploit-attempts is beginning to gather force. E-mail security company Message Labs, for instance, has detected a more than 50 percent increase in what it describes as "suspicious DNS traffic" over the last few weeks.

Like everybody else, bMighty has been talking about the DNS problem for awhile, and the fact that we're still talking about unpatched DNS servers -- and especially unpatched servers at major ISPs -- indicates that we'll continue to do so for awhile yet.

Not sure about your own ISP's DNS server? There's a tester button on Dan Kaminsky's homepage that's worth a click. (He's added an experimental mail server test as well.)


Security
Business & E-Business | IT | Internet/Web | Messaging | Networking & Communications | Server How-To | bMighty




This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




Explore ANTenna Blog
Most Recent Posts
ANTenna Blog Topics
     
     
ANTenna Bloggers
ANTenna Blog Roll


 


Browse by Category

IW SMB Tech
Term Of Day:

Boost your tech
vocabulary!
InformationWeek SMB's
TechEncyclopedia
defines more than
20,000 IT terms.



FREE Technology Services Locator!

Search our database of 200,000 solution- provider locations by business activity, technology, vertical market, and customer size. Find a technology partner NOW.

go