Most Popular Stories
- 3 ways for CIOs to become business leaders
- Chrome 17's new features enhance speed, security
- FBI insists cloud providers meet strict security requirements
- Multiple monitors makes some multitasking faster, easier
- Bug in Trendnet webcams exposes them to public viewing
- Spotlight: Intel launches 520 Series solid-state drive
Events
- The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA - Customer Engagement Technology World
March 28-29, 2012 — San Francisco - Northwestern University Master's in Information Systems
- COMPTEL PLUS Spring 2012
April 15-18 — San Francisco, CA
Sponsored Links
Free Newsletter
HOT TOPICS >> Tech world's top flops and fiascos of 2011 | Windows 8 slideshow | Cybersecurity | Caron's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
FierceCIO provides CIOs with IT best practices, business intelligence, and forward-looking IT strategies. Join 32,000+ industry insiders who get FierceCIO twice a week via email and save time.
About | View Sample | Privacy
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Five Tips to Get IT Auditors Off Your Back
- Case Study: ABBYY FineReader® Engine Drives Demand for ECM Software Leader
- Is Corporate Liability Robbing YOU Blind?
- Whitepaper: 10 Reasons You Absolutely Need AD Reporting
- The Top 4 Reasons Your Telecom Expense Management Provider Shouldn't Manage Your Wireless
DNS flaws opens the door to an array of attacks
Security researcher Kaminsky, who first discovered the DNS exploit that had organizations around the world scrambling to patch their Domain Name Servers (DNS), spoke to a packed session at the Black Hat conference this week. He took the opportunity to describe a dizzying array of attacks that can result from an exploited DNS. Two attack vectors caught my attention: one is the fact that even SSL connections are not impervious to a DNS-based attack. Kaminsky noted that "[c]ompanies that issue SSL certificates use Internet services like e-mail and the Web to validate their certificates."
The second vulnerability is described as a "forgot my password" style attack. Criminals could claim to have forgotten a user's password to get a site to send out a user's password. DNS hacking techniques could then be exploited to trick the targeted site into sending the secret password to the hacker's computer.
To learn more about DNS-based attack vectors:
- check out this NetworkWorld article
Related Stories
- Exploit code for DNS flaw released
- Lotus Notes catches a bug
- UCLA making databases less sensitive, more secure
- IE flaw could prove troublesome
- Microsoft pushes for worm patch
- Researcher finally gets his security warning heard
- Phishers using BBC news to infect PCs
- How to really know your security risks
- OpenBSD Founder: Contractor tried to write back doors
- Firefox add-on Firesheep facilitates hijacking of Facebook, Twitter sessions
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




