InternetFaster Attacks Break DNS Patches in Under 10 Hours (NewsFactor)
NewsFactor - The Internet remains vulnerable to exploits of a critical security flaw in the Domain Name System, a Russian programmer demonstrated last week. Writing on his blog on Friday, Evgeniy Polyakov posted that he had succeeded in getting patched DNS software to return an incorrect location in less than 10 hours.
The Internet remains vulnerable to exploits of a critical security flaw in the Domain Name System, a Russian programmer demonstrated last week. Writing on his blog on Friday, Evgeniy Polyakov posted that he had succeeded in getting patched DNS software to return an incorrect location in less than 10 hours. His work shows that DNS patches, which had appeared to solve the immediate problem, are insufficient. Cache Poisoning At the Black Hat security conference in Las Vegas last week, Dan Kaminsky, director of penetration testing for IOActive, detailed a vulnerability that makes the DNS vulnerable to cache-poisoning attacks, in which a DNS is tricked into rerouting traffic to a malicious Web site. Once users have been taken to the malicious site, a criminal could load their computers with a range of malware. The vulnerability has actually been around for years, but Kaminsky developed a quicker, more efficient and more reliable means to implement the attack. Patches were developed and everyone running a DNS server was urged to implement the them. But with Polyakov's discovery, are the patches now useless? The patches deployed as a result of Kaminsky's findings "have always been intended to deliver risk reduction, not entire risk elimination," Andrew Storms, director of security operations for nCircle Network Security, said in an e-mail. A Question of Speed According... [ Read more on www.yahoo.com ]
InternetIkea Sets Up Mobile Shop in Britain
Retail giant offers pay as you go wireless service.
InternetGoogle resolves Gmail access problems (Reuters)
Reuters - Google Inc said on Monday it has resolved an issue with its contacts system that caused many users of its Gmail service to have trouble accessing their online e-mail.
