"There are a lot of people out there," Kaminsky began as he scanned the audience. "Holy cr**!"
The attack could be used to send Internet users to malicious sites or hijack e-mail.
To characterize the seriousness of the flaw, Kaminsky quoted security researcher Brad Hill's assessment: "Remember how pissed you were when you found out that the NSA had rooms where they could read everything? That's every kid right now."
As Kaminsky explained during his presentation, DNS is basically the Internet's version of 411. So being able to alter the associations between domain names and IP addresses allows malicious attackers to control where online information gets routed.
"Everything breaks when DNS breaks," said Kaminsky.
Following his July 8 announcement, Kaminsky said that he planned to reveal details about the vulnerability at the Black Hat conference on Wednesday, Aug. 6, and he encouraged security researchers to refrain from speculating about the withheld details, to give those with vulnerable systems time to patch.
But on Monday, July 21, security researcher Halvar Flake posted his guess about how the DNS vulnerability worked on his blog. Then a security researcher at Matasano Security corrected some of the details in his own blog post. That prompted US CERT to warn that technical details about the DNS vulnerability had been released and to urge Internet users to patch vulnerable systems immediately.
Upon learning about the disclosure, Kaminsky in a blog post responded, "Patch. Today. Now. Yes, stay late."
What wasn't revealed until today was that another security researcher, Pieter de Boer, found the bug only 51 hours after Kaminsky's initial announcement. As it turns out, there are at least 15 known ways to run this attack and, Kaminsky suggested, perhaps 20 more undiscovered ways. So Kaminsky's effort to keep the flaw secret to buy time, derided by some, now looks even wiser.
The security community's commitment to fix the DNS bug appears to be working. On July 8 and 9, 85% of the unique name servers submitting to a self-test on Kaminsky's blog were vulnerable. As of July 25, that number had dropped to just over 50%.
![]()
![]()
![]()
![]()
![]()
![]()
![]()
Windows Jingle Attack Exposed
![]()
Reporters Ejected, Accused Of Hacking
![]()
Ian Angell: Security Offers Illusion Of Control
![]()
Come Together, Over Security
![]()
![]()
![]()
Page 2:
Who's Still Vulnerable?
![]()
1
|
2
Next Page »
Stay connected and informed by visiting the CA Solutions Center Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.