Details of DNS Glitch Slip into the Wild
Six months ago, security expert Dan Kaminsky stumbled upon a flaw so serious and widespread that it could bring the entire internet crashing down — at least for those on the wrong side of the bug. Two weeks ago, he publicly announced the bug, which affects the Domain Name System or DNS, with plans to release details of the exploit itself during the annual Black Hat Briefings in Las Vegas. On Monday, those plans were preempted when a security firm involved in the repairs posted full details of the issue online, making way for exploits to hit the web by Wednesday.
The flaw — for which hackers now have at least two active exploits — allows attackers to trick DNS servers into sending traffic intended for legitimate sites to ones setup by the attacker, and to do so transparently. It has been suggested that the attack would take all of ten seconds. As is usually the case, many researchers and network administrators refused to believe Kaminsky's reports, instead declaring him a glory hound merely rehashing an already discovered exploit. Among those was Thomas Ptacek, founder of the security firm that disclosed the flaw, Matasano — Ptacek later apologized for the premature disclosure, saying the responsible blog post had been written in anticipation of Kaminsky or someone else disclosing the flaw, and was accidentally published.
Regardless of why the details leaked out two weeks early, all parties — especially those who spent their time attacking Kaminsky instead of patching their networks — are sorry now. Anyone out there who hasn't already learned of the glitch and patched their network is encouraged to do so immediately, and individual users would be wise to check that the DNS servers they use have been updated as well. To quote Kaminsky, as everyone is:
Justin Ryan is a Contributing Editor for Linux Journal.
Trending Topics
| You Need A Budget | Feb 10, 2012 |
| The Linux powered LAN Gaming House | Feb 08, 2012 |
| Creating a vDSO: the Colonel's Other Chicken | Feb 06, 2012 |
| Your CMS Is Not Your Web Site | Feb 01, 2012 |
| Casper, the Friendly (and Persistent) Ghost | Jan 31, 2012 |
| Razor-qt 0.4 - Qt based Desktop Environment | Jan 30, 2012 |
- Fun with ethtool
- Parallel Programming with NVIDIA CUDA
- Readers' Choice Awards 2011
- 100% disappointed with the decision to go all digital.
- Linux-Based X Terminals with XDMCP
- Validate an E-Mail Address with PHP, the Right Way
- You Need A Budget
- The Linux powered LAN Gaming House
- Why Python?
- Python for Android





3 hours 4 min ago
4 hours 25 min ago
7 hours 8 min ago
11 hours 39 min ago
16 hours 45 min ago
17 hours 46 min ago
1 day 3 hours ago
1 day 3 hours ago
1 day 9 hours ago
1 day 12 hours ago