NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Security Fixes and Improvements

Security Fixes and Improvements


Patch for the Internet Core Flaw Is also Flawed

Proof-of-concept exploit for the patch was released

By Lucian Constantin, Web News Editor

9th of August 2008, 09:03 GMT

Adjust text size:


DNS Patch is flawed
Enlarge picture
Yesterday, Russian physicist Evgeniy Polyakov posted on his blog a proof-of-concept exploit that is able to insert poisoned DNS entries into a patched server. His setup consisted of two desktop computers and a GigE connection. The successful exploit took place in a bit under 10 hours, which could mean that less time would be necessary with a more powerful setup.

Earlier this year, Dan Kaminsky, a security researcher, discovered a security flaw in DNS (Domain Name System) that posed a huge risk to the entire Internet. The industry rushed to come up with a solution and, in early July, they released a patch.

Kaminsky released his findings only to a number of big companies, refusing to offer technical details about this vulnerability to the general public until August at a conference in Vegas, when he also revealed that this flaw might not only affect the web, but also other services like e-mail.

Since first announced, this vulnerability has generated a lot of controversy. Security analysts noted that attacks have already been carried out and more will follow. These attacks focused on distribution of malicious software and phishing for personal information, which put financial organizations at risk.

Estimates say that the patch for this vulnerability has been installed on 3/4 of the servers worldwide, but Mr. Polyakov's example goes to show that this doesn't make much of a difference. To be more exact, without the patch, an attack could be carried out in seconds, while with the patch it becomes a matter of hours. Paul Mockapetris, the developer of the original DNS, commented that the implementation of this patch is like "playing Russian roulette with a gun that has 100 bullet chambers instead of six."

Experts are trying to come up with other, more stable solutions. One of these proposed solutions is DNSSEC, which offers encryption-based addressing and that has already been implemented by some governments, like the Swedish one. However, DNSSEC poses implementation problems for commercial internet because it requires a more solid server infrastructure and a lot more resources compared with normal DNS. This makes DNSSEC a real solution only in the long run, as it can't be introduced and adopted overnight.

Others think there are better alternatives to DNSSEC, like Daniel J. Bernstein, a mathematician who developed a DNS version that is not affected by this flaw. His opinion about DNSSEC is that it "offers a surprisingly low level of security, while at the same time introducing performance and reliability problems."

TAGS:

DNS Flaw | Internet Vulnerability | DNS Patch | BIND | Kaminsky
Read by 1,662 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Very Good (4.6/5) 3 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Email Security Threatened by DNS Flaw

Sabre Security CEO Figures Out DNS Vulnerability

Six-Year-Old Internet Vulnerability Still Active

Kaminsky Faces Security and Hacking Community Scorn

DNS Flaw Finally Fixed

Almost Flawless DNS Scams

DNS cache poisoning

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM