The Cellar  

Go Back   The Cellar > Main > Technology
FAQ Community Calendar Today's Posts Search

Technology Computing, programming, science, electronics, telecommunications, etc.

Reply
 
Thread Tools Display Modes
Old 12-01-2008, 08:15 PM   #1
Elspode
When Do I Get Virtual Unreality?
 
Join Date: Dec 2002
Location: Raytown, Missouri
Posts: 12,719
Fascinating Scary Shit Most of Us Never Heard About

...like a DNS exploit that some code mensch stumbled upon and shook up people who know stuff.

http://www.wired.com/techbiz/people/...?currentPage=1

Quote:
Then last January, on a drizzly Sunday afternoon, he flopped down on his bed, flipped open his laptop, and started playing games with DNS. He used a software program called Scapy to fire random queries at the system. He liked to see how it would respond and decided to ask for the location of a series of nonexistent Web pages at a Fortune 500 company. Then he tried to trick his DNS server in San Diego into thinking that he knew the location of the bogus pages.

Suddenly it worked. The server accepted one of the fake pages as real. But so what? He could now supply fake information for a page nobody would ever visit. Then he realized that the server was willing to accept more information from him. Since he had supplied data about one of the company's Web pages, it believed that he was an authoritative source for general information about the company's domain. The server didn't know that the Web page didn't exist—it was listening to Kaminsky now, as if it had been hypnotized.
__________________
"To those of you who are wearing ties, I think my dad would appreciate it if you took them off." - Robert Moog
Elspode is offline   Reply With Quote
Old 12-01-2008, 09:34 PM   #2
ZenGum
Doctor Wtf
 
Join Date: Oct 2007
Location: Badelaide, Baustralia
Posts: 12,861
So ... was it the real Elspode who started this thread, then?
__________________
Shut up and hug. MoreThanPretty, Nov 5, 2008.
Just because I'm nominally polite, does not make me a pussy. Sundae Girl.
ZenGum is offline   Reply With Quote
Old 12-01-2008, 10:07 PM   #3
Cloud
...
 
Join Date: Feb 2007
Posts: 8,360
does the maggot cheese count?
__________________
"Guard your honor. Let your reputation fall where it will. And outlive the bastards!"
Cloud is offline   Reply With Quote
Old 12-02-2008, 06:02 AM   #4
tw
Read? I only know how to write.
 
Join Date: Jan 2001
Posts: 11,933
This DNS vulnerability is why your on-line banking accounts have a picture you want to confirm before logging in. This unique Kaminsky attack simply exampled the much larger problem that had been ignored for some time by the industry. Few considered DNS to be a security weakness.
tw is offline   Reply With Quote
Old 12-02-2008, 08:46 PM   #5
classicman
barely disguised asshole, keeper of all that is holy.
 
Join Date: Nov 2007
Posts: 23,401
Quote:
Originally Posted by tw View Post
This DNS vulnerability is why your on-line banking accounts have a picture you want to confirm before logging in. This unique Kaminsky attack simply exampled the much larger problem that had been ignored for some time by the industry. Few considered DNS to be a security weakness.
Damn MBA's getting into everything these days, aren't they?
__________________
"like strapping a pillow on a bull in a china shop" Bullitt
classicman is offline   Reply With Quote
Old 12-05-2008, 03:27 PM   #6
footfootfoot
To shreds, you say?
 
Join Date: Aug 2004
Location: in the house and on the street-how many, many feet we meet!
Posts: 18,449
I broke the intarwebz and all I got was this lousy orange jumpsuit?
__________________
The internet is a hateful stew of vomit you can never take completely seriously. - Her Fobs
footfootfoot is offline   Reply With Quote
Old 12-05-2008, 07:32 PM   #7
Elspode
When Do I Get Virtual Unreality?
 
Join Date: Dec 2002
Location: Raytown, Missouri
Posts: 12,719
It is widely known that DNS vulnerabilities are due to management failures.
__________________
"To those of you who are wearing ties, I think my dad would appreciate it if you took them off." - Robert Moog
Elspode is offline   Reply With Quote
Old 12-05-2008, 08:58 PM   #8
footfootfoot
To shreds, you say?
 
Join Date: Aug 2004
Location: in the house and on the street-how many, many feet we meet!
Posts: 18,449
Quote:
Originally Posted by Elspode View Post
It is widely known that 85% of DNS vulnerabilities are directly traceable to top management failures.
__________________
The internet is a hateful stew of vomit you can never take completely seriously. - Her Fobs
footfootfoot is offline   Reply With Quote
Old 12-05-2008, 10:36 PM   #9
tw
Read? I only know how to write.
 
Join Date: Jan 2001
Posts: 11,933
Quote:
Originally Posted by Elspode View Post
It is widely known that DNS vulnerabilities are due to management failures.
NY Times discussed this problem and temporary solution almost four month ago in early August in "Leaks in Patch for Web Security Hole ".
Quote:
The general risk of such a flaw had been known for some years within the insular Internet technical community. But in the last month security engineers have repeatedly stated that it is only a matter of time before financial organizations and others are attacked by computer criminals seeking to exploit the now-public flaw. One expert says this is happening now.
The problem has been known for much longer than anyone cared to admit.
Quote:
The root of the problem lies in the fact that the address system, which was invented in 1983, was not meant for services like electronic banking that require strict verification of identity.
They are relying on infrastructure that was not intended to do what people assume it does,” said Clifford Neuman, director of the Center for Computer Systems Security at the University of Southern California. “What makes this so frustrating is that no one has been listening to what we have been saying for the past 17 years.”
A solution still has not been implemented.
Quote:
Mr. Mockapetris described the patch that is now being put in place as the equivalent of “playing Russian roulette with a gun that has 100 bullet chambers instead of six.”
tw is offline   Reply With Quote
Old 12-05-2008, 11:28 PM   #10
dar512
dar512 is now Pete Zicato
 
Join Date: May 2003
Location: Chicago suburb
Posts: 4,968
It is widely known that 85% of all statistics are made up on the spot.
__________________
"Against stupidity the gods themselves contend in vain."
-- Friedrich Schiller
dar512 is offline   Reply With Quote
Old 12-06-2008, 12:24 AM   #11
classicman
barely disguised asshole, keeper of all that is holy.
 
Join Date: Nov 2007
Posts: 23,401
Well tw, 1% is far better odds than 16.666%. Don't ya think?
__________________
"like strapping a pillow on a bull in a china shop" Bullitt
classicman is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

All times are GMT -5. The time now is 10:38 AM.


Powered by: vBulletin Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.