DNS software hole allows Web attacks

The flaw in two widely used versions of BIND (Berkeley Internet Name Domain), distributed free by the Internet Software Consortium (ISC), could be exploited immediately by unscrupulous programmers if they can write a program to take advantage of it, said Jim Magdych, security research manager at the Computer Vulnerability Emergency Response Team (COVERT) at PGP Security, a Network Associates business. Developing this might take only a few days, he said.

COVERT and ISC, along with Carnegie-Mellon University's Computer Emergency Response Team (CERT) Coordination Centre, will shortly announce a fix for the vulnerability and plan by that time to have the fix available on ISC's Web page, http://www.isc.org/. The flaw was discovered a few weeks ago, Magdych said.

"If this just showed up in the wild, it could have a pretty serious impact on the Internet at large," Magdych said.

The vulnerability exists in versions 4 and 8 of BIND, the software used in "the vast majority" of DNS servers, though not in the recently released version 9, Magdych said.

DNS servers translate the commands used to access Internet resources, such as Web URLs (Universal Resource Locators) and e-mail addresses, into numbered IP (Internet Protocol) addresses. The TSig (Transaction Signatures) vulnerability lets hackers take control of DNS servers and command them to redirect or block Internet requests sent to them.

A TSig attack could have effects similar to those of the denial-of-service attacks that kept users from reaching Microsoft Web sites last week, or even more serious effects, Magdych said. For example, hackers could take over a financial Web site, re-create the site's login screen, and direct user names and passwords to a server where they could be stolen.

Skilled hackers who break in to corporate DNS servers could block or redirect e-mail and even sabotage access to corporate databases over Internet-based company intranets.

"This is probably the most significant vulnerability to date in BIND," he said. "It's really important that everyone who's affected by this either applies the patch or upgrades to BIND 9."

All hackers will need to do is write a program that sends certain messages as requests to DNS servers. The messages would be interpreted as commands that would open up the server to exploitation.

Although the vulnerability is a subtle one, there are hackers who could act on it quickly if made aware of it, Magdych said.

"When a new vulnerability is discovered, it's just a matter of time before someone develops a program to exploit that vulnerability. Those exploits are then distributed by the community of crackers," or unscrupulous hackers, Magdych said.

"It's certainly not going to be something that takes months. Among our adversaries there are some very talented individuals," he said.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Stephen Lawson

PC World

Comments

Comments are now closed.

Most Popular Reviews

Follow Us

Best Deals on GoodGearGuide

Shopping.com

Latest News Articles

Resources

GGG Evaluation Team

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Steph Mundell

LIFEBOOK UH574

The Fujitsu LifeBook UH574 allowed for great mobility without being obnoxiously heavy or clunky. Its twelve hours of battery life did not disappoint.

Andrew Mitsi

STYLISTIC Q702

The screen was particularly good. It is bright and visible from most angles, however heat is an issue, particularly around the Windows button on the front, and on the back where the battery housing is located.

Simon Harriott

STYLISTIC Q702

My first impression after unboxing the Q702 is that it is a nice looking unit. Styling is somewhat minimalist but very effective. The tablet part, once detached, has a nice weight, and no buttons or switches are located in awkward or intrusive positions.

Latest Jobs

Shopping.com

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?