Most Popular Stories
Events
Sponsored Links
Latest News
Popular Topics
Whitepapers
- IT Service Management: Aligning IT and Business Goals for the High-Performance Hospital
- IM and Presence: Achieving Mission Critical Status in the Enterprise
- How Social Computing, Team Collaboration, and Enterprise Content Management Drive Competitive Advantage
- Service Oriented Architecture
- Collaboration and Social Media: Taking Stock of Today's Experiences and Tomorrow's Opportunities
- HIPAA Security Provisions
DNS flaws opens the door to an array of attacks
Security researcher Kaminsky, who first discovered the DNS exploit that had organizations around the world scrambling to patch their Domain Name Servers (DNS), spoke to a packed session at the Black Hat conference this week. He took the opportunity to describe a dizzying array of attacks that can result from an exploited DNS. Two attack vectors caught my attention: one is the fact that even SSL connections are not impervious to a DNS-based attack. Kaminsky noted that "[c]ompanies that issue SSL certificates use Internet services like e-mail and the Web to validate their certificates."
The second vulnerability is described as a "forgot my password" style attack. Criminals could claim to have forgotten a user's password to get a site to send out a user's password. DNS hacking techniques could then be exploited to trick the targeted site into sending the secret password to the hacker's computer.
To learn more about DNS-based attack vectors:
- check out this NetworkWorld article
Related Stories
- Exploit code for DNS flaw released
- Lotus Notes catches a bug
- UCLA making databases less sensitive, more secure
- IE flaw could prove troublesome
- Microsoft pushes for worm patch
- Researcher finally gets his security warning heard
- Phishers using BBC news to infect PCs
- IETF mulls the option of ignoring Kaminsky DNS bug
- Critical vulnerability opens electrical grids to attack
- Top CIO concerns
Comments
Post new comment
Home
| Subscribe | Advertise | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceSarbox | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceBiotech | FierceBioResearcher | FiercePharma | FierceVaccines | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe© 2008 FierceMarkets, Inc. All rights reserved. |
![]() |





