Home / News I have a News Tip

Largest Synchronized Internet Security Effort Underway to Patch Newly Found DNS Bug

A fundamental flaw in the design of the Domain Name System (DNS) was found earlier this year by security researcher Dan Kaminsky, renowned Internet Security expert. Researchers say they will fully describe the vulnerability in 30 days, after companies that operate web sites or Internet service providers can put the patches in place. The flaw is big enough that Kaminsky and other companies involved brought in government agencies such as the Department of Homeland Security and the U.S. Computer Emergency Response Team. Until the announcement today, experts had been quietly working on coordinating a massive patch affecting all types DNS implementation. Experts emphasized during the press conference today that the flaw is within the DNS protocol and in no way specific to any particular vendor.

Sources:
• A related DNS checker tool is available on Kaminsky's website located on the top right hand corner.
• Vulnerability announcement from CERT: Multiple DNS implementations vulnerable to cache poisoning
• ISC Press Release on BIND: ISC acts quickly to shield BIND user base
• Related podcast interview with Dan Kaminsky
OpenDNS service recommended as a safe alternative DNS service to those of ISPs
DNSstuff Freeware Detects Vulnerable DNS Servers
Black Hat Webcast

Updates:
Alliance forms to fix DNS poisoning flaw 7/8/2009 - SecurityFocus
Mulitple Vendors DNS Spoofing Vulnerability 7/8/2008 - Internet Storm Center
Related discussions on Slashdot 7/8/2008 - Slashdot
Major DNS flaw could disrupt the Internet 7/8/2008 - Network World
Kaminsky and Ptacek comment on DNS flaw 7/8/2008 - ZDNet
An Astonishing Collaboration 7/9/208 - CircleID
Internet Bug Fix Spawns Backlash From Hackers 7/9/2008 - PC World
Who's Really at Risk From the DNS Flaw? 7/10/2008 - InternetNews
DNS researcher convinces skeptics that bug is serious 7/11/2008 - ComputerWorld
The man who changed Internet security 7/14/2008 - CNet
Not a Guessing Game 7/14/2008 - CircleID
RHN Bind Update Brings Down RHEL Named 7/18/2008 - Slashdot
Has Halvar figured out super-secret DNS vulnerability? 7/21/2008 - ZDNet
Kaminsky's DNS Attack Disclosed, Then Pulled 7/21/2008 - Slashdot
DNS Security Flaw Secret Leaked Prior to Set Date: Patch DNS as Fast as Possible 7/21/2008 - CircleID
DNS Attack Code Has Been Published 7/23/2008 - CircleID
Kaminsky suggests long-term fix will still have to be determined 7/24/2008 - ZDNet
Day 30: Kaminsky DNS Bug Disclosure 8/6/2008 - CircleID

Read full story: External Source

Related topics: Cybersecurity, DNS, DNS Security

 
   

Don't miss a thing – get the Weekly Wrap delivered to your inbox.

Comments

Patch Tuesday Larry Seltzer  –  Jul 08, 2008 2:16 PM PDT

Is this the DNS bug that was patched today by Microsoft?

Yes according to reports Ali Farshchian  –  Jul 08, 2008 2:43 PM PDT

Larry, yes according this and probably other sources which I havn't had time to look into:

One of the Microsoft fixes for Windows DNS was part of a group of patches issued today by software vendors to plug a multi-platform hole. The researcher who uncovered the vulnerability called the group patch effort the "largest synchronized security update in the history of the Internet."

Yep David A. Ulevitch  –  Jul 08, 2008 4:26 PM PDT

Larry — Yes it was.

http://blog.opendns.com/ has some of our perspective. :-)

Partly DNS, but also nameserver randomization, correct? Christopher Parente  –  Jul 09, 2008 2:27 PM PDT

Quite the big news yesterday! Not everyone was vulnerable, as I bet the previous commenter points out via his URL.

Here's my attempt to describe the problem to a broader audience:
http://cparente.wordpress.com/2008/07/09/its-tuesday-must-be-time-to-fix-dns/

To post comments, please login or create an account.

Related Blogs

Related News

Explore Topics

Dig Deeper

Verisign

Cybersecurity

Sponsored by Verisign
Afilias Mobile & Web Services

Mobile Internet

Sponsored by Afilias Mobile & Web Services
Afilias

DNS Security

Sponsored by Afilias

Promoted Posts

Now Is the Time for .eco

.eco launches globally at 16:00 UTC on April 25, 2017, when domains will be available on a first-come, first-serve basis. .eco is for businesses, non-profits and people committed to positive change for the planet. See list of registrars offering .eco more»

Industry Updates – Sponsored Posts

Verisign Named to the Online Trust Alliance's 2017 Audit and Honor Roll

Attacks Decrease by 23 Precent in 1st Quarter While Peak Attack Sizes Increase: DDoS Trends Report

Leading Internet Associations Strengthen Cooperation

Global Domain Name Registrations Reach 329.3 Million, 2.3 Million Growth in Last Quarter of 2016

Verisign Releases Q4 2016 DDoS Trends Report: 167% Increase in Average Peak Attack from 2015 to 2016

Neustar to be Acquired by Private Investment Group Led by Golden Gate Capital

Verisign Q3 2016 DDoS Trends Report: User Datagram Protocol (UDP) Flood Attacks Continue to Dominate

2016 U.S. Election: An Internet Forecast

Government Guidance for Email Authentication Has Arrived in USA and UK

ValiMail Raises $12M for Its Email Authentication Service

Don't Gamble With Your DNS

Defending Against Layer 7 DDoS Attacks

Understanding the Risks of the Dark Web

New TLD? Make Sure It's Secure

Verisign Releases Q2 2016 DDoS Trends Report - Layer 7 DDoS Attacks a Growing Trend

How Savvy DDoS Attackers Are Using DNSSEC Against Us

Radix Adds Dyn as a DNS Service Provider

Facilitating a Trusted Web Space for Financial Service Professionals

MarkMonitor Partners with CYREN to Deepen Visibility into Global Phishing Attacks

Verisign Named to the Online Trust Alliance's 2016 Honor Roll