NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Server related

Server related


Email Security Threatened by DNS Flaw

Warns the IOActive specialist who discovered the bug

By Denisa Ilascu, Internet / SEO News Editor

7th of August 2008, 12:34 GMT

Adjust text size:


Email security is threatened by a DNS flaw that allows hackers to intercept messages
Enlarge picture
Dan Kaminsky is the IOActive specialist whose speech was the most anticipated at this year's Black Hat hacker conference held in Las Vegas. This happened because, one month ago, Kaminsky announced that he had discovered a DNS flaw that employed completely new methods to steal data and affect users' connections. When all those either too curious or too impatient attempted to find out what it was all about, including here hack attempts, Kaminsky asked for more time and vouched he would unveil everything at the Las Vegas conference.

Yesterday, in a speech held in front of a very large audience, Kaminsky did indeed offer some details on the Internet flaw, which brings some risks that users have never been exposed to before. One of these is the possibility that people be redirected to unsolicited websites, despite typing in the right URL. Users cannot control the access they have, because the packets with bad information are attached directly to the data flow that goes back and forth through the DNS servers. Hackers can use this weakness in the DNS server to redirect users to advertising websites enabled with automatic clicking. The illicit activity lines the criminals' pockets, while depriving users of the control over their online activity.

The Associated Press reports that Kaminsky also described another threat to users' online security, caused by the same bug. Email messages can be intercepted by hackers and redirected to their own servers. This because email routing implies an MX record request and this type of record is also DNS based. As the researcher said, access to email account information can give even more leverage to the hackers. One advantage is that they can get the passwords for all the websites the attacked user ever subscribes to, since it's already a known fact that people can ask for password retrieval using their email.

Major companies have already applied patches to their servers, but Kaminsky warned at the conference and on his blog that people could not protect themselves, as the firewall proved to be inefficient against the bug. "There are enough variants of the bug that we needed a stopgap before working on something more complete," he said.

TAGS:

DNS flaw | Dan Kaminsky | email security | firewall | Black Hat
Read by 1,213 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


US Won't Turn Over Control Of Internet DNS

Sabre Security CEO Figures Out DNS Vulnerability

Six-Year-Old Internet Vulnerability Still Active

Kaminsky Faces Security and Hacking Community Scorn

DNS Flaw Finally Fixed

Almost Flawless DNS Scams

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM