Home » 

UK ISP News Archives

 » 
Sponsored Links

UPD: Firms Scramble to Patch Major DNS Internet Security Flaw

Posted: 09th Jul, 2008 By: MarkJ
UPDATE: Microsoft's MS08-037 DNS patch has apparently crippled users of the popular ZoneAlarm Firewall - forum post. ZA is recommending that people uninstall the patch until it has a fix.

It's just been revealed that the Internet's Domain Name System (DNS), which is responsible for translating Internet Protocol (IP) addresses into human readable form (e.g. "87.106.71.228" becomes "ispreview.co.uk") and vica versa, has had a serious underlying security flaw for several months.

The flaw, which could allow hackers to redirect your browsing activity to fake webpage’s and thus make phishing attacks even easier, was first discovered at the start of this year by security expert Dan Kaminsky (blog):

"It's not good, this class of attack is known as cache poisoning and basically an attacker can go ahead and impersonate large chunks of the web or large chunks of the internet to a random user," warned Kaminsky.

Kaminsky subsequently began informing all of the major firms and DNS management systems about the flaw, which included Microsoft, Cisco, Sun and Bind. Since then they and Kaminsky have been working in secret to develop and rollout a multi-vendor patch to solve the problem across all platforms, which finally went live yesterday evening.

Part of the reason for all the secrecy is to avoid hackers being made aware of the fault before it could be fixed, which would have made the Internet incredibly vulnerable. Happily there have been no reported incidents of this particular flaw being exploited and precise details are likely to be kept under wraps until August.

The delay in disseminating information about the flaw is designed to give the patch some breathing room for deployment. Meanwhile the patch has also been made difficult to reverse engineer, thus hindering hackers’ ability to discover the fault before it can be fully deployed.

Internet users need not be too concerned about the problem, although people should always be vigilant. To that end, Kaminsky has made a DNS check available on his blog that allows you to test whether your connection / network may be vulnerable.
Search ISP News
Search ISP Listings
Search ISP Reviews
Cheap BIG ISPs for 100Mbps+
Community Fibre UK ISP Logo
100Mbps
Gift: None
Virgin Media UK ISP Logo
Virgin Media £22.99
132Mbps
Gift: First 3 Months Free
Vodafone UK ISP Logo
Vodafone £23.00
150Mbps
Gift: None
Youfibre UK ISP Logo
Youfibre £23.99
150Mbps
Gift: None
Sky UK ISP Logo
Sky £24.00
100Mbps
Gift: None
Large Availability | View All
Cheapest ISPs for 100Mbps+
Gigaclear UK ISP Logo
Gigaclear £17.00
300Mbps
Gift: None
toob UK ISP Logo
toob £18.00
150Mbps
Gift: None
Community Fibre UK ISP Logo
100Mbps
Gift: None
Lightning Fibre UK ISP Logo
150Mbps
Gift: None
Virgin Media UK ISP Logo
Virgin Media £22.99
132Mbps
Gift: First 3 Months Free
Large Availability | View All
Sponsored Links
The Top 15 Category Tags
  1. FTTP (6723)
  2. BT (3863)
  3. Politics (3039)
  4. Business (2736)
  5. Openreach (2629)
  6. Building Digital UK (2489)
  7. Mobile Broadband (2435)
  8. FTTC (2132)
  9. Statistics (2103)
  10. 4G (2063)
  11. Virgin Media (1997)
  12. Ofcom Regulation (1762)
  13. 5G (1693)
  14. Fibre Optic (1587)
  15. Wireless Internet (1581)
Sponsored

Copyright © 1999 to Present - ISPreview.co.uk - All Rights Reserved - Terms  ,  Privacy and Cookie Policy  ,  Links  ,  Website Rules