Security
Experts are warning of a major DNS vulnerability

Major DNS flaw revealed

Experts sound alarms over early disclosure

Written by Shaun Nichols in San Francisco

Patch. Today. Now. Yes, stay late

Dan Kaminsky Security researcher

A high-profile security flaw scheduled for disclosure next month has been released early, much to the chagrin of security experts.

Researcher Dan Kaminsky had originally planned to disclose details about the vulnerability at next month's Black Hat conference in Las Vegas.

The vulnerability lies in the basic components of the Domain Name System and could allow a hacker to use a 'cache poisoning' attack to redirect traffic without the user's knowledge.

Kaminsky said that, although he had known about the vulnerability for months, he had not publicly released any details to allow vendors time to patch the flaw and prevent the attack.

Vendors had responded well to the policy, coordinating a major patch release earlier this month. By last week, reports surfaced that a number of ISPs had either already patched the flaw or were in the process of doing so.

Yesterday, however, the grace period ended when a self-proclaimed DNS novice blew the gaff. Reverse engineering specialist Halvar Flake posted a theory which turned out to be Kaminsky's DNS flaw.

Researchers are now urging administrators who have not patched the flaw to install updates as soon as possible.

"Since this now means the bad guys have access to it at will, the urgency of patching your recursive DNS servers just increased significantly," said Sans researcher Swa Frantzen.

A posting on Kaminsky's blog said: "Patch. Today. Now. Yes, stay late." The US Computer Emergency Readiness Team has posted a set of guidelines for mitigating the flaw on unpatched servers.

The disclosure of the vulnerability was not exactly intentional. Flake was reading through a basic DNS text in his spare time and posted a blog on Monday speculating on the possible flaw.

"I have done pretty much no protocol work in my life, so I have little hope for having gotten close to the truth," he wrote.

As it turns out, Flake's speculation was right on. Security firm Matasano briefly posted a blog entry confirming Flake's hypothesis. Shortly after, the posting was removed and the company issued an apology for the confirmation.

"Dan told me about his finding personally in order to help ensure widespread patching before further details were announced at the upcoming Black Hat conference," wrote Matasano principal Thomas Ptacek.

"That I helped detract from that work is painful both personally and professionally, and I apologize to Dan for the way this played out."

Flake, however, issued no such apologies. The researcher noted that the information embargo assumed that malware writers would not discover and exploit the flaw before the Black Hat conference.

"I respect Dan Kaminsky's viewpoint, but I disagree that this buys anyone time," Flake wrote.

"If nobody speculates publicly, we are pulling the wool over the eyes of the general public and ourselves. We are not buying anybody time; we are buying people a warm and fuzzy feeling."

See also:

reader comments

related articles

MicrosoftSecurity

Microsoft issues monthly security pack

Nothing 'critical' about July update 09 Jul 2008

 

Icann downplays recent site hacks

Redirects were 'limited', says organisation 08 Jul 2008

Twin Trojans attack Macs

Malware spotted in the wild 21 Jun 2008

Shape-shifting malware hits the web

Cyber-criminals changing malware signatures every few hours 15 May 2008

DNS exploit haunts researcher

Local ISP attack affects BreakingPoint 31 Jul 2008

Exploit emerges for DNS flaw

First attack tool created for vulnerability 25 Jul 2008

Apple misses mark on DNS patch

Leopard remains vulnerable to cache poisoning, say researchers 05 Aug 2008

latest news

Resellers hit by delivery disruption as Amtrak fails

UK courier company Amtrak has entered receivership due to financial difficulty 29 Aug 2008

Dell’s profits plunge 17 per cent

PC vendor's net profit takes a tumble as turf war with HP in EMEA hurts bottom line 29 Aug 2008

Avnet upgrades and expands Bracknell demo centre

Distributor refurbishes five-year-old centre to provide vastly expanded proof-of-concept opportunities 29 Aug 2008

poll

A new Linksys era?

A new Linksys era?

Will the Linksys brand fizzle out when Cisco folds it into its SME operation?

Previous poll results

In The Studio With CRN: Josh Claman, Dell

In an editorial coup for CRN, Josh Claman, vice president of EMEA channels at Dell, talks to CRN TV about the vendor's channel plans

CRN Fight Night bouts are LIVE!

ALL the bouts from CRN's first ever white collar boxing event at The Brewery in Chiswell Street, are now online in their full glory for CRN readers to watch.

events

CRN Golf Challenge 2008

CRN Channel Golf Challenge 2008

CRN's annual golfing day will this year be held on 16 September at a championship course in East Sussex

CRN Reseller Leadership Forum logo

CRN Reseller Leadership Forum

An exclusive channel conference from CRN, to be held over one action-packed day in September 2008

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories