Home / News

Kaminsky Bug One Year Later: DNS Still Vulnerable

Carolyn Duffy Marsan of Network World reporting: "A year has passed since security researcher Dan Kaminsky disclosed a serious flaw in the DNS that makes it possible for hackers to launch cache poisoning attacks… Experts say more has been done to bolster the security of the DNS in the past 12 months than in the previous decade, thanks to Kaminsky's discovery. Yet, the DNS remains as vulnerable as ever to cache poisoning attacks."

Read full story: Network World

Related topics:

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

Pushing DNSSEC Alessandro Vesely  –  Jul 29, 2009 3:27 AM PDT

Hadn't the Kaminsky bug been fixed already? That was a short-term fix, as the article says (emphasis added)

The long-term fix for Kaminsky-style attacks is DNSSEC, which prevents cache poisoning attacks by allowing Web sites to verify their domain names and corresponding IP addresses using digital signatures and public-key encryption.

Actually, it seems easier to poison mail sites because it is much easier to guess what queries a mail server is going to issue after receiving an SMTP connection. Curiously, mail sites are not considered. In addition, mail operators already complain about bandwidth and cycles required to process the amount of DNS information intended to counter spam, such as DNSBL, SPF, DKIM, etcetera. DNSSEC is not going to make that much lighter. Curiously, DNS over SCTP is not being considered either.

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

There are no company postings related to this page yet. Contact us to learn more about having your company news and updates featured on CircleID. Learn More

Hot Topics

Neustar UltraDNS

DNS

Sponsored by
Neustar UltraDNS
Afilias

DNS Security

Sponsored by
Afilias
Nominum

IPv6

Sponsored by
Nominum
Verisign

Security

Sponsored by
Verisign
dotMobi

Mobile

Sponsored by
dotMobi
Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines