NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security

Security


Six-Year-Old Internet Vulnerability Still Active

Flaw dating back to 2002 still being detected

By George Craciun, Security News Editor

18th of July 2008, 09:09 GMT

Adjust text size:


Ari Tanaken draws attention to 2002 vulnerability
Enlarge picture
For the past week or so, Dan Kaminsky and the DNS (Domain Name System) flaw that he discovered have made the headlights of numerous online publications. Although specific, technical details about the flaw have yet to be disclosed, the IT industry assures us that the 8th of July patch has solved the problem. Founder and CTO of Codenomicon, company that specializes in providing security testing software, Ari Takanen does not agree.

Does anyone remember the SNAPv1 (Simple Network Management Protocol version 1) flaw that came to light back in 2002? The DNS and SNAP flaws both address fundamental issues in regard to the Internet, and they have much more in common than you might think.

"Our SNMP case was secret for nine months after reporting it to relevant vendors, and as far as I know it involved more than 100 vendors and other organizations (1,000+ people). We saw all possible attempts to disclose it, but even public disclosure lists appreciated the stand that CERT-US chose to take," says Takanen as cited by CNet.

Ari Takanen’s affirmations came in response to an article published by Robert Vamosi, in which he stated that never before a flaw with such a major impact has been discovered. Several industry heavyweights studied the problem for a period of six months and then issued a fix simultaneously.

The interesting thing is that, to this day, Codenomicon still detects the six-year-old flaw, despite the general belief that all vulnerable systems have been patched. Although the flaw received so much media coverage in 2002, there are still systems out there that are vulnerable to this now ancient flaw.

"This just proves that reporting individual bugs for fame and fortune does not motivate the vendors to improve their quality assurance processes," says Ari Takanen, who strongly believes against disclosing security flaws before a fix is issued.

TAGS:

Codenomicon | vulnerabilities | DNS | security
Read by 807 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


XP SP3 RC1 and RC2 Still Available for Download

The Eset Way of Keeping Infection Free

Samsung Chairman Gets $109 Million Fine

Phishing Attack Uses IRS as a Front

The Bourne Conspiracy Cheats and Unlockables (Xbox 360)

XP SP3 and Vista SP1: DirectX 9 and DirectX 10 Patches Updated

The Name Behind the Gmail Address

Get Your Site Out of Google's Blacklist

Over 1,000 Trusted, Government and NHS Sites Compromised

The Most Spammed American States Awards

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM