DNS disaster: first attacks reported

The first attacks that are likely to have stemmed from a serious Domain Name System flaw have been reported.

Dan Kaminsky
(Credit: Kaminsky's blog)

The existence of the Domain Name System (DNS) flaw, which could be used to redirect browsers to malicious sites, was revealed at the start of July by security researcher Dan Kaminsky. Multiple vendors, including Microsoft and Cisco, have already issued patches to counteract any attacks.

However, code that could act as a blueprint for an attack via the flaw was published on Wednesday last week by Metasploit, which provides penetration-testing tools. On Friday last week, a user named James Kosin posted an excerpt from a server log to a Fedora Linux mailing list, claiming it proved attacks based on the DNS flaw had begun.

"The DNS attacks are starting," read Kosin's post. "Below is a snippet of a logwatch from last night. Be sure all DNS servers are updated if at all possible. The spooks are out in full on this security vulnerability in force. This is your last warning... Patch or upgrade now!"

Approached via email to discuss his post, Kosin appeared to retreat from saying the activity he had observed was definitely an attack. "I can't prove or disprove any claim that it is an exploit of the flaw other than to say it started about a week ago," he told ZDNet.com.au sister site ZDNet.co.uk. "I'd already updated the server's DNS application, so I'm taking an educated stab in the peripheral internet here in saying it is a good possibility of being a possible exploit."

Carl Leonard, a threat research manager for the security company Websense, who reported Kosin's post, said his company had still not seen any attack reports in its own systems. However, he said Websense does "expect to" see such reports. "The exploit code is available and people still need to patch systems," he said. "It's kind of a waiting game at the moment."

The flaw in question is inherent to the DNS - the part of the internet's infrastructure that takes a human-readable web-address request and finds the corresponding numeric IP address. The nodes of the DNS are nameservers and, if one of those is left unpatched, the new attack code could fool the server into redirecting user requests to phishing sites or other malware-hosting sites.

Those who need to apply the patch are mostly internet service providers (ISPs) and companies that run their own nameservers. Users can check if their nameservers are vulnerable through a tool hosted on Kaminsky's blog.

Advertisement

Talkback 5 comments

    What attacks? Enough with the DNS hype!Anonymous -- 29/07/08

    This article mentions a guy who said he was attacked and then backed off from his comments, big time. But hey, when you can get "disaster" and "attacks" into a headline, why not just do it!?

    This DNS flaw is the most over-hyped security bug in history. Both BIND 9 and MS DNS have had similar issues within the last 12 months -- between them they must handle at least 90% of the world's domain queries. Why no fuss then??

    Not HypeAnonymous -- 31/07/08 (in reply to #320107933)

    This is not "over-hype". That's all I'll say. And the only reason I'm saying that much is in hopes that those in charge of a DNS server will upgrade. All the major DNS vendors, *including* MS and BIND are saying there's a critical exploit and you need to patch. What more do you need? These are the creators of the DNS service...Jesus.

    And MS accounts for a *very* small portion of public DNS servers.

    EavesdropperAnonymous -- 29/07/08

    From Dam Kaminsky's profile pic it appears he's trying to eavesdrop on his neighbours by putting his ear close to a wall.

    RE: EavesdropperAnonymous -- 30/07/08 (in reply to #320107977)

    "From Dam Kaminsky's profile pic it appears he's trying to eavesdrop on his neighbours by putting his ear close to a wall."

    HILARIOUS! You've inspired me to hold a "Caption Contest" for this photo - comment well made!

    Not an attackGraeme Fowler -- 30/07/08

    Kosin's log extracts, if he'd looked at them in full instead of yelling about it, came from a machine in a respected .edu domain with links to Kaminsky - and if the reporter dug a bit further he'd have seen several fingerprints showing them to be obvious data collection linked to Doxpara's (Kaminsky's firm) age-old DNS scan project. I have confirmed this with Kaminsky and I'm sure he'd be happy to confirm it by email with others, if only they'd ask...

    No wonder Kosin has "appeared to retreat".

    The sky isn't falling - yet.

Add your opinion


Latest Videos

Blogs

  • Juha Saarinen TelstraUnClear
    Telstra's New Zealand arm TelstraClear is one strange company ...
  • Array E-health too unsexy for COAG
    There will always be something more politically sexy than e-health for state governments, meaning the National E-Health Transition Authority's business case for a national electronic medical record might just sit on the shelf gathering dust forever.
  • Array Will Rudd's bush backhaul bonanza deliver?
    Rural areas will be welcoming the government's decision to put its money where its politicising is, funnelling $250m into a regional fibre upgrade to six rural centres. Remedying over a decade of near-neglect at the hands of telecoms privatisation, the investment could be the firmest step yet for Labor's NBN dream — but with inevitable political questions and a looming election, Rudd and Conroy need to deliver, and quickly, to preserve the NBN's credibility.
  • More blogs »

Tags

Back to top

Featured