News

Attack Code Released For New DNS Attack

Attack code has been released for a major flaw in the Internet's DNS software

By Robert McMillan, IDG News Service (San Francisco Bureau)

Page 2

Although a software fix is now available for most users of DNS software, it can take time for these updates to work their way through the testing process and actually get installed on the network.

"Most people have not patched yet," said ISC President Paul Vixie in an e-mail interview earlier this week. "That's a gigantic problem for the world."

Metasploit's code looks "very real," and uses techniques that were not previously documented said Amit Klein, chief technology officer with Trusteer.

It will probably be used in attacks, he predicted. "Now that the exploit is out there, combined with the fact that not all DNS servers were upgraded... attackers should be able to poison the cache of some ISPs," he wrote in an e-mail interview. "The thing is -- we may never know about such attacks, if the attackers... work carefully and cover their tracks properly."

Other stories by Robert McMillan

DNS

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors