Black Hat: DNS Flaw Opened Up Many Possible Attacks

At the Black Hat conference, Internet security guru Dan Kaminsky described a dizzying array of attacks that could exploit the DNS flaw that he recently brought to light, plus the work he's been doing to shore up critical Internet services.

By Robert McMillan on Thu, August 07, 2008
Tweet it!
Email
Digg
Share this article
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

IDG News Service — There were 6 a.m. calls from Finnish certificate authorities and also some pretty harsh words from his peers in the security community, even an accidentally leaked Black Hat presentation, but after managing the response to one of the most highly publicized Internet flaws in recent memory, Dan Kaminsky said Wednesday that he'd do it all over again.

Kaminsky's full-time job over the past few months has been working with software vendors and Internet companies to fix a widespread flaw in the DNS (domain name system), used by computers to find each other on the Internet. Kaminsky first disclosed the problem on July 8, warning corporate users and Internet service providers to patch their software as quickly as possible.

On Wednesday, he disclosed more details of the issue during a crowded session at the Black Hat conference, describing a dizzying array of attacks that could exploit DNS. Kaminsky also talked about some of the work he'd done to fix critical Internet services that could also be hit with this attack.

By exploiting a series of bugs in the way the DNS protocol works, Kaminsky had figured out a way to very quickly fill DNS servers with inaccurate information. Criminals could use this technique to redirect victims to fake Web sites, but in Kaminsky's talk he described many more possible types of attacks.

He described how the flaw could be used to compromise e-mail messages, software updating systems or even password recovery systems on popular Web sites.

And though many had thought that SSL (Secure Socket Layer) connections were impervious to this attack, Kaminsky also showed how even the SSL certificates used to confirm the validity of Web sites could be circumvented with a DNS attack. The problem, he said, is that the companies that issue SSL certificates use Internet services like e-mail and the Web to validate their certificates. "Guess how secure that is in the face of a DNS attack," Kaminsky said. "Not very."

"SSL's not the panacea we would like it to be," he said.

Another major problem has been what Kaminsky says is the "forgot my password" attack. This affects many companies that have Web-based password recovery systems. Criminals could claim to have forgotten a user's password to the Web site and then use DNS hacking techniques to trick the site into sending the password to their own computer.

In addition to the DNS vendors, Kaminsky said he'd worked with companies such as Google, Facebook, Yahoo and eBay to fix the various problems related to the flaw. "I do not want to see my cell phone bill this month," he said.

Continue Reading

black hat

Get up to speed on mobile security.

Learn More »
Loading...
Most Recent Security Stories
The path to creating a secure application begins by rigorously testing source code for all vulnerabilities and ensuring that use of the application does not compromise or allow others to compromise data privacy and integrity.
The reasons for outsourcing application development are many and varied. Outsourcing can be a cost effective and efficient solution to the demand for new and specialized applications in todays Internet-based marketplace. It is absolutely critical, however, that the team responsible for evaluating the outsourced application makes security one of its principal criteria prior to acceptance of each release.
The path to creating a secure application begins by rigorously testing source code for all vulnerabilities and ensuring that use of the application does not compromise or allow others to compromise data privacy and integrity.
Enterprises understand the importance of securing web applications to protect critical corporate and customer data. What many dont understand, is how to implement a robust process for integrating security and risk management throughout the web application software development lifecycle.
Watch an online demo of iPrism and you'll get a $20 Amazon gift card as our way of saying thanks.
Online fraud is a non-stop threat to organizations around the globe, and cybercriminals have no intention of slowing down the pace. Also, global are likely to have an impact on the evolution of cybercrime. Read this special online fraud report for information about the latest online fraud trends and what to expect and prepare for in the future.
Key IT Security & Authentication Concerns for 2010
Data protection is a bigger challenger for small and midsize businesses. You need to protect sensitive data, but la...
Privacy and Data Protection Practices
Moderated by CSO Publisher, Bob Bragdon, hear from this esteemed panel as they share practical approaches to simpli...
Avoid common pitfalls and learn strategies for ensuring a successful PCI audit from information security and compli...
Protecting critical data is now the imperative at most every organization. As more and more laws are passed and reg...
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Sponsored Links

Simplifying Risk Management: Is Your Company Measuring Up?

Attend Microsoft's Windows 7 Virutal Event for a change to win a Microsoft Zune HD. Register Now!

Ready to create safe, business class social networking tools? View Now

Let Progress Software help your business make progress.

Register for more Windows Enterprise Webcasts today.

Entrust IdentityGuard  Strong Authentication for your Enterprise

Supercharge Your End Users with Desktop Virtualization

Take the Netezza TwinFin TestDrive!

Best Practices to Reduce IT Operational Costs

Maximizing efficiencies with unified communications.

Taking the Service Desk to the Next Level

Getting ready to upgrade to Windows 7? Attend Microsoft's Virtual Event on 4/22 for all the tools you'll need. Register Now!

Read report on how to improve decision making with business analytics.

Dynamic Virtual Client: Whats in store for client technology going forward?

The ISP that focuses exclusively on information security? SecureWorks.

Does your IDS really work? Find out with a free Endace Audit

CA ARCserve r12.5 is More Than Backup! Download Trial Version Today

Enterprise search helps employees get more done. Get the facts from Google.

Real-world testing ranks Trend Micro #1 against malware. See results.

Dark Fiber from Sunesys Save on Unlimited Bandwidth with Fixed Costs.

Trend Micro ranked #1 against real-world malware. Read more.

How Healthcare CIOs Achieve a High-Performance Emergency Department

Webcast: Solve Your Data Visualization Needs with Open Source BI

Webcast: Delivering the Enterprise-Ready Cloud

Ensure cost effective application delivery. Learn More.

Trend Micro ranked #1 against real-world malware. Read more.

March 31st Webcast: "Product Development and the Cross-Functional Team"

Get to know Supermicro. Business-optimized server solutions.

Google Webinar: Why Cloud-Based Security and Archiving Make Sense

HP pays back. Trade in your old printer and get up to $1000

Counting Up the End User Benefits of Desktop Virtualization

Build a smart, practical path to the internal cloud.

Verint Systems. Discover the Power of Intelligence in Action"

Efficiency goes up. Costs come down.

Achieving Business Agility with Application Grid

Seven Ways ITIL Can Help You in an Economic Downturn

Midsized company CIOs and experts connect at infoBOOM!

Core" i5 vPro" Processor: Control meets cost savings in the most intelligent PC processors ever!

Article: The Dynamic Virtual Client offers thin client advantages with rich client user experience & mobility.

Manage limitless content todayread EMCs 15-minute guide to ECM.

HP Exstream. Get a Free Document Assessment for Financial Services.

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

See why ShoreTel is named best overall VoIP provider by Nemertes Research

Turn your desk phone and mobile phone into one with Sprint Mobile Integration.

Stay informed with custom newsletters from Tech Dispenser

Get ready for your Windows 7 upgrade at this live, virtual event. Register Now!

Selecting the Right Reporting Technology

An IT Leadership Action Plan for the Economic Recovery

Consolidate data centers and lower IT service costs. Learn How.

WAN optimization techniques significantly improve application performance. Read More.

Resource Center