Version: 2008

July 31, 2004 4:50 PM PDT

Internet's 'white pages' allow data attacks

  • 4 comments
LAS VEGAS--The same technology that allows Web surfers to locate and connect to computers on the Internet can be used to create covert communications channels, bypass security measures and store distributed content, a security researcher said Saturday.

The security hack essentially uses data transferred by domain name service (DNS) servers to hide additional information in the network communications. DNS servers act as the white pages of the Internet, invisibly transforming easy-to-remember domain names--such as www.cnet.com--into the numerical network addresses used by computers. Moreover, corporate security measures, such as firewalls, tend to ignore DNS data because they assume it's harmless, said Dan Kaminsky, a security researcher for telecommunications firm Avaya and a speaker at the Defcon hacking conference here.

"DNS is everywhere--you cannot communicate over the global Internet without knowing where to go," he said. "No one notices DNS. No one monitors it."

That flaw in most companies' network security leaves a vulnerability that can be used by hackers to sneak intellectual property outside a company, communicate with a compromised server inside the company, or gain free access to many wireless and Internet services found in coffee houses and hotels, he said.

Covert channels are an area of research for both security experts and hackers. Last year, another security expert demonstrated a way to send dribs and drabs of data across the Internet by hiding them in network packets. The concept goes back at least 15 years, but the Avaya security researcher has actually created useful tools for people who want to send covert messages over DNS.

At Defcon, Kaminsky showed off server software that acts as a communications hub for covert messages and a program that can insert data into DNS requests. Using the software, he could send instant messages over an encrypted communications channel carried by spoofed DNS requests. He also showed off broadcasting streaming radio over the covert channel.

The data will not normally be recorded or detected by network security, Kaminsky said, because it appears to just be legitimate DNS servers communicating with one another.

"The user is not actually sending data outside the network," he said. "They (seem to be) requesting data from the local DNS server and it is sending it outside the network."

There are other security side effects to network administrators not paying attention to DNS packets. Online services that allow a user to connect to the Internet after logging into a captive portal--such a system allows wireless users to get on the Internet at Starbucks--allow DNS packets to pass through the security. That means that a hacker could use Kaminsky's software to get free wireless access on most such networks.

Network administrators should pay more attention to DNS, said Kaminsky. Servers infected with the MSBlast worm, for example, used the service to look up the address of Microsoft's Windowsupdate.com server, and that made DNS a good method for detecting compromised computers.

"We have known that this is feasible for years," he said. "It's time to pay attention."

Add a Comment (Log in or register) (4 Comments)
  • prev
  • 1
  • next
This is only the beginning!
by OneWithTech August 1, 2004 10:14 AM PDT
This exploit is one of many that you will be seeing in the next year. We, as web developers, are only beginning to learn the inner-most workings of the world wide web. The javascript injection exploit as posted by Secunia Secure (http://secunia.com/advisories/11978/) had been around for a long time but only exploited just recently. With that said, I hope those that are in the business of twisting technology to find the flaws, continue to break this digital world. I know I will!
Reply to this comment
But why?
by bradleyland August 2, 2004 8:08 AM PDT
Have you ever heard the saying, "locks are for honest people." In the "real" world, security relies - to a certain extent - upon the implicit honesty of the individual. What's stopping you from breaking into the store you pass on the street? A piece of glass? Glass is exploitable you might say. The thing keeping you from breaking into the store is your implicit honesty, and the realization that this is someone else's property. Somehow this gets lost on the web. I just don't get it.
View reply
DNS can be exploited for email too
by ttul November 30, 2004 7:34 PM PST
One use of DNS that should no go without mention is the routing of email. DNS can be manipulated to route email in funny ways that solve some of the most difficult problems facing the email world these days -- like spam and phishing. Check out http://www.mailchannels.com for an example of using DNS in a very new way.
Reply to this comment
(4 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (0.03%) 3.10 10,548.51
S&P 500 (0.02%) 0.22 1,126.42
NASDAQ (0.13%) 2.88 2,291.28
CNET TECH (0.22%) 3.61 1,664.74
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right