The Cellar

The Cellar (http://cellar.org/index.php)
-   Technology (http://cellar.org/forumdisplay.php?f=7)
-   -   Fascinating Scary Shit Most of Us Never Heard About (http://cellar.org/showthread.php?t=18878)

Elspode 12-01-2008 08:15 PM

Fascinating Scary Shit Most of Us Never Heard About
 
...like a DNS exploit that some code mensch stumbled upon and shook up people who know stuff.

http://www.wired.com/techbiz/people/...?currentPage=1

Quote:

Then last January, on a drizzly Sunday afternoon, he flopped down on his bed, flipped open his laptop, and started playing games with DNS. He used a software program called Scapy to fire random queries at the system. He liked to see how it would respond and decided to ask for the location of a series of nonexistent Web pages at a Fortune 500 company. Then he tried to trick his DNS server in San Diego into thinking that he knew the location of the bogus pages.

Suddenly it worked. The server accepted one of the fake pages as real. But so what? He could now supply fake information for a page nobody would ever visit. Then he realized that the server was willing to accept more information from him. Since he had supplied data about one of the company's Web pages, it believed that he was an authoritative source for general information about the company's domain. The server didn't know that the Web page didn't exist—it was listening to Kaminsky now, as if it had been hypnotized.

ZenGum 12-01-2008 09:34 PM

So ... was it the real Elspode who started this thread, then?

Cloud 12-01-2008 10:07 PM

does the maggot cheese count?

tw 12-02-2008 06:02 AM

This DNS vulnerability is why your on-line banking accounts have a picture you want to confirm before logging in. This unique Kaminsky attack simply exampled the much larger problem that had been ignored for some time by the industry. Few considered DNS to be a security weakness.

classicman 12-02-2008 08:46 PM

Quote:

Originally Posted by tw (Post 509851)
This DNS vulnerability is why your on-line banking accounts have a picture you want to confirm before logging in. This unique Kaminsky attack simply exampled the much larger problem that had been ignored for some time by the industry. Few considered DNS to be a security weakness.

Damn MBA's getting into everything these days, aren't they?

footfootfoot 12-05-2008 03:27 PM

I broke the intarwebz and all I got was this lousy orange jumpsuit?

Elspode 12-05-2008 07:32 PM

It is widely known that DNS vulnerabilities are due to management failures.

footfootfoot 12-05-2008 08:58 PM

Quote:

Originally Posted by Elspode (Post 511116)
It is widely known that 85% of DNS vulnerabilities are directly traceable to top management failures.


tw 12-05-2008 10:36 PM

Quote:

Originally Posted by Elspode (Post 511116)
It is widely known that DNS vulnerabilities are due to management failures.

NY Times discussed this problem and temporary solution almost four month ago in early August in "Leaks in Patch for Web Security Hole ".
Quote:

The general risk of such a flaw had been known for some years within the insular Internet technical community. But in the last month security engineers have repeatedly stated that it is only a matter of time before financial organizations and others are attacked by computer criminals seeking to exploit the now-public flaw. One expert says this is happening now.
The problem has been known for much longer than anyone cared to admit.
Quote:

The root of the problem lies in the fact that the address system, which was invented in 1983, was not meant for services like electronic banking that require strict verification of identity.
They are relying on infrastructure that was not intended to do what people assume it does,” said Clifford Neuman, director of the Center for Computer Systems Security at the University of Southern California. “What makes this so frustrating is that no one has been listening to what we have been saying for the past 17 years.”
A solution still has not been implemented.
Quote:

Mr. Mockapetris described the patch that is now being put in place as the equivalent of “playing Russian roulette with a gun that has 100 bullet chambers instead of six.”

dar512 12-05-2008 11:28 PM

It is widely known that 85% of all statistics are made up on the spot.

classicman 12-06-2008 12:24 AM

Well tw, 1% is far better odds than 16.666%. Don't ya think?


All times are GMT -5. The time now is 09:50 AM.

Powered by: vBulletin Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.