Skip to content
#12
Auto-translated
Worldwide Internet Hack Prevented
07/09/2008 12:53 | lenta.ru


Several major IT corporations, including Microsoft, Sun, and Cisco, have coordinated the release of a patch that fixes a serious vulnerability in DNS, the system responsible for matching internet addresses to domain names, ZDNet reports. By exploiting this flaw, attackers could redirect traffic from virtually any web address to their own servers.

The DNS flaw was discovered by security specialist Dan Kaminsky of IOActive about six months ago. He decided to share this information directly with the relevant companies, and during the discussion, he requested that they release a patch simultaneously.

Kaminsky is currently refusing to disclose details about the vulnerability, but the general mechanism of the hack became clear from questions and answers at a conference, CNet reports. There are 13 main DNS servers in the world and many servers that update their databases in accordance with the main ones. Each request for the IP address corresponding to a given domain is assigned a random identification number from 0 to 65,000.

According to Kaminsky, an attacker can guess this number and forge a server's response. In this case, a user would be redirected, for example, to a fake bank server or online store.

After the fix, the identification number will become almost impossible to guess – their distribution will be closer to random, and 32 bits will be allocated for each number instead of 16.

You can check your DNS server for the vulnerability, which has been dubbed DNS Cache Poisoning, at doxpara.com. It is expected that the vast majority of personal computers will be automatically protected from DNS Cache Poisoning within thirty days.

Statistics

Welcome our newest member: dodoD0D0

Users Online 2 users 1395 guests