NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security

Security


Sabre Security CEO Figures Out DNS Vulnerability

Matasano Security acknowledges, then takes it all back

By George Craciun, Security News Editor

22nd of July 2008, 09:41 GMT

Adjust text size:


Halvar Flake may have discovered how the DNS flaw works
Enlarge picture
Recently, the DNS flaw discovered by Dan Kaminsky made all the headlines, first of all because of its gravity, and secondly because the Director of Penetration Testing for IOActive would not release specific, technical details about the flaw. Kaminsky stated on numerous occasions that he would disclose all the information on the 6th of August, at the BlackHat Security Conference in Las Vegas. But it seems that Thomas Dullien, CEO and head of research with Sabre Security has figured it all out, even though he admits he is not an expert in DNS.

This is the message posted on the Matasano Security blog in regard to Dullien's discovery: "The cat is out of the bag. Yes, Halvar Flake figured out the flaw Dan Kaminsky will announce at Black Hat". Halvar Flake is the hacker alias used by Thomas Dullien. It must be noted that the blog post presented above was posted for about five minutes and then it was taken down.

Thomas Ptacek from Matasano Security has posted another statement on the site, saying that they "dropped the ball" and it was all a regrettable error. "Earlier today, a security researcher posted their hypothesis regarding Dan Kaminsky's DNS finding. Shortly afterwards, when the story began getting traction, a post appeared on our blog about that hypothesis. It was posted in error. We regret that it ran. We removed it from the blog as soon as we saw it. Unfortunately, it takes only seconds for Internet publications to spread," says Ptacek.

According to Halvar Flake, there is no good reason behind Kaminsky's request not to publicly speculate on the DNS vulnerability. He agrees that Kaminsky did the right thing by not disclosing the vulnerability and getting the industry heavyweights to come up with a fix, but by not speculating you are not buying the user any time. "In a strange way, if nobody speculates publicly, we are pulling wool over the eyes of the general public, and ourselves," says Halvar Flake.

Dan Kaminsky did not confirm or deny the fact that Hlavar Flake had indeed discovered the DNS vulnerability that he came upon earlier this year, and he is urging all users to update, if they haven't done so already. On the 24th Kaminsky will do a webcast for BlackHat, but he says this opportunity will not be used to disclose details on the DNS vulnerability. All those interested in the issue will have to wait until the 6th of August.

TAGS:

DNS | Sabre Security | data leak | security
Read by 1,147 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


The Nominees for the 2008 Pwnie Awards

Iranian Hackers Try to Silence Malcolm Hoenlein

Intego Aims VirusBarrier X5 at iPhone 2.0

Stolen Blackberry Puts Downing Street Servers in Peril

Citizens Bank Online Out of Service

Bioshock - Hints (Xbox 360)

Successful Hacker Attack on Kaspersky Malaysia

President of Georgia Web Page Down after Hacker Attack

The Spanish Police Warns About Pro-Anorexia Websites

How the UN Keeps Its Network Safe

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM