• On MP3.com: Worst MP3 Players of 2007
July 24, 2008 6:10 AM PDT

DNS exploit code is in the wild

As of Wednesday, an exploit code allowing someone to attack the domain name system (DNS) was available in various places on the Internet.

On July 8, IOActive researcher Dan Kaminsky disclosed a flaw in the DNS but would not provide the details until all the affected vendors had released patches and all the systems worldwide could be patched. He figured that it would take about 30 days for that to happen.

The 30-day mark just happened to coincide with his speaking engagement at Black Hat in Las Vegas on August 6.

But on Monday, fellow Black Hat presenter Halvar Flake attacked Kaminsky's plea that a security flaw such as this be kept a secret. Flake then proceeded to lay out what he thought the flaw was. Turns out, he was right and laid the foundation for others to create and publicize an exploit.

On Thursday, Kaminsky will be a guest on the second Black Hat Webinar. This is the second of what is hoped to be a monthly series produced by the conference. Kaminsky will be joined by Jerry Dixon, former director of the Department of Homeland Security's cybersecurity division; Rich Mogull, founder of Securosis; and Joao Damas, a senior program manager at the Internet Systems Consortium. The Webinar begins at 1 p.m. PT.

To see if your connection to the Internet is vulnerable to DNS cache posioning, use this test on Kaminsky's site. As of Monday, researcher Neal Krawetz was reporting that servers at several high-profile ISPs remained vulnerable.

Recent posts from News - Security
D-Day for RFID-based transit card systems
Data breaches best 2007 record
Study: Uptick in spam-sending zombie PCs in September
Spam volume down in September
Two Europeans indicted over U.S. cyberattacks
Add a Comment (Log in or register) 10 comments
by jamalystic July 24, 2008 6:42 AM PDT
Well now that Kaminsky's solution is public, don't you think the bad guys will figure how this work and try to circumvent it in the future as this expert suggested: DNS Revolutions & Evolutions(http://www.internetevolution.com/author.asp?section_id=495&doc_id=158621&F_src=flftwo)
Reply to this comment
by livecrunch July 24, 2008 6:52 AM PDT
I notified my IT staff week ago about it. But also isn't this something we are already dealing with for past 10 years now?
Reply to this comment
by n3td3v July 24, 2008 6:59 AM PDT
I guess HD Moore doesn't like Dan Kaminsky very much since he told people like HD Moore not to release such code until after the Blackhat Conference.

Where does this leave HD Moore on the world stage as responsible security researcher? Oh wait, he isn't one and never was a responsible security researcher.

Metasploit frame work is used primarily by the bad guys, so we can see what HD Moore's intentions are.

In other news, why isn't HD Moore in jail yet?
Reply to this comment
by Seaspray0 July 24, 2008 7:13 AM PDT
My suggestion is to not trust any transaction that isn't secured with an SSL certificate from a trusted root certificate authority. The SSL is tied to the DNS name of the website. While the DNS flaw may be able to redirect you to a bogus IP for that site, it won't have the SSL certificate of the original site.
Reply to this comment
by GlennF July 24, 2008 10:09 AM PDT
Re: Livecrunch: No, this is a different problem. If I understand the history correctly, more than a decade ago, two problems were fixed: insufficient randomization of transaction IDs, and the ability to provide additional RRs that include domains outside the domain being queried. This attack allows an in-domain attack.

Re: n3td3v: I don't know that I agree with your statement or with HD Moore's behavior overall, but Moore released practical exploitation code only after Matasano Chargen posted a blog entry that explained the attack with great specificity. Moore is doing a service by allowing penetration/vulnerability testing with a common tool now that the knowledge is in the hands of black hats.

Re: Seaspray0: Great suggestion. Also, DNSSEC is finally moving forward, which would allow signing of information among DNS servers, and thus defeat any known poisoning attack.
Reply to this comment
by n3td3v July 24, 2008 12:31 PM PDT
re:GlennF

To me HD Moore is a black hat though who is just using a loop hole in the law to make the Metasploit frame work and to distribute exploit code to the other bad guys.

If Metasploit was a legitimate attack platform, it would only be available to companies with credentials who can prove who they are and that they have permission and legitimate reason to use Metasploit for the small amount of folks who use Metasploit for legal above board reasons.

With Metasploit, anyone can walk off the street and download it and thats got to be a bad thing, but im not entirely sure that HD Moore cares about the bad guys using Metasploit, as long as he is known as an elite hacker and is worshipped like a god.
Reply to this comment
by The_Decider July 24, 2008 2:08 PM PDT
Metasploit is a legitimate academic and pentest platform as well.

Nearly every network tool that is used legitimately has illegitimate uses also. With your logic wireshark, nessus, dsniff, nikto, hydra, nmap, ettercap,netstumbler. kismet, various fuzzers, etc should all be banned and its authors jailed. Don't stop there, we should ban network and programming security courses from CS depeartments and jail all of us who can write tools that can be used for evil.
Reply to this comment
by cohaver July 25, 2008 8:30 AM PDT
Windows New Desktop Search Faces the Same Problems as this. Notice the latest update to Vista Desktop Search software
Reply to this comment
by Tsee July 25, 2008 11:09 PM PDT
Kaminsky's site recommends OpenDNS, which is NOT open-source.
Reply to this comment
by pmbx July 27, 2008 6:53 AM PDT
I'm tired of 'black hat experts' just looking for exploits to gain notoriety. I'm ready for the first lawsuits against Kaminsky for real damages that occurred because of his irresponsibility. He put his own self-interests first in order to be the one to blast this dns deficiency on the stage. It all about the bucks he'd get from his 'expertise.' All these security 'experts' are probably the same. Why isn't there legislation to make this kind of action worthy of jail time!
Reply to this comment
Powered by Jive Software
advertisement
Click Here
Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

About News - Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

News - Security topics

Featured blogs

advertisement

Inside CNET News

Scroll Left Scroll Right