Details of DNS Glitch Slip into the Wild

July 25th, 2008 by Justin Ryan

Your rating: None

Six months ago, security expert Dan Kaminsky stumbled upon a flaw so serious and widespread that it could bring the entire internet crashing down — at least for those on the wrong side of the bug. Two weeks ago, he publicly announced the bug, which affects the Domain Name System or DNS, with plans to release details of the exploit itself during the annual Black Hat Briefings in Las Vegas. On Monday, those plans were preempted when a security firm involved in the repairs posted full details of the issue online, making way for exploits to hit the web by Wednesday.

The flaw — for which hackers now have at least two active exploits — allows attackers to trick DNS servers into sending traffic intended for legitimate sites to ones setup by the attacker, and to do so transparently. It has been suggested that the attack would take all of ten seconds. As is usually the case, many researchers and network administrators refused to believe Kaminsky's reports, instead declaring him a glory hound merely rehashing an already discovered exploit. Among those was Thomas Ptacek, founder of the security firm that disclosed the flaw, Matasano — Ptacek later apologized for the premature disclosure, saying the responsible blog post had been written in anticipation of Kaminsky or someone else disclosing the flaw, and was accidentally published.

Regardless of why the details leaked out two weeks early, all parties — especially those who spent their time attacking Kaminsky instead of patching their networks — are sorry now. Anyone out there who hasn't already learned of the glitch and patched their network is encouraged to do so immediately, and individual users would be wise to check that the DNS servers they use have been updated as well. To quote Kaminsky, as everyone is:

“Patch. Today. Now. Yes, stay late.”
Editor's Note: If you don't know if your DNS server is safe or not, a testing tool is available on Kaminsky's site. We are also aware of two DNS providers that have been confirmed as never having been susceptible to the exploit: OpenDNS and PowerDNS. If the vulnerability test shows your DNS server as vulnerable, you may wish to switch to one of those until yours can be patched.

__________________________

Justin Ryan is News Editor for LinuxJournal.com.
Submit a tip: EmailIRC


Special Magazine Offer -- 2 Free Trial Issues!
Receive 2 free trial issues of Linux Journal as well as instant online access to current and past issues. There's NO RISK and NO OBLIGATION to buy. CLICK HERE for offer

Linux Journal: delivering readers the advice and inspiration they need to get the most out of their Linux systems since 1994.

Sorry, offer available in the US only. International orders, click here.

Post new comment

Please note that comments may not appear immediately, so there is no need to repost your comment.
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <pre> <ul> <ol> <li> <dl> <dt> <dd> <i> <b>
  • Lines and paragraphs break automatically.

More information about formatting options

Featured Videos

The November 13, 2008 edition of Linux Journal Live! Shawn Powers and special guest, Linux Journal Author Daniel Bartholomew, talk e-book readers and Daniel's Kindle, DRM, and other goodness.

From the Magazine

December 2008, #176

The Oxford English Dictionary says the word "gadget" is a placeholder name for a technical item whose precise name one can't remember. Like that book-reader thingy from Amazon...what's it called? Spindle, Gindle...Kindle, that's it. Check it out in this month's gadget issue.

Other gadgets covered include the Nokia tablets, the BlackBerry, the Neo FreeRunner, the Dash Express, the Roku Netflix Player, the Kangaroo TV, The TomTom GO 930 and the MooBella Ice Cream System. On the larger hardware front, read the reviews of the Acer Aspire One and the YDL PowerStation. On the software front, check out the articles and columns on memcached, Samba security, Mutt, desktop gadgets, bash and Puppet. To wrap it all up, read Doc's thoughts on Google and the browser platform.

Read this issue

Sign up for our Email Newsletter