The Domain Name Server design flaw that threatened the entire Internet earlier this year has mostly been patched, but the threat is far from over, experts say. The DNS flaw, which was discovered by IOActive researcher Dan Kaminsky in the first half of this year and resulted in the largest simultaneous security software patch in Internet history in July, was fully disclosed last month.
The flaw makes it possible for attackers to exploit the recursive nature of DNS server queries to “hijack” TCP/IP sessions and potentially redirect large segments of Internet traffic to unintended destinations. Threat From DNS Bug Isn’t Over, Experts Say - Desktop Security News Analysis - Dark Reading
From around the Web
- Users not patching third party apps
- Mozilla patches 12 Firefox bugs, a third of them critical
- IE 7 and 8 Default Security Leaves Intranets At Risk
- Microsoft ships fixes for Excel, WordPad malware attacks
- 15 Firefox addons for Web developers
- Windows 7 will nag users 29% less often, Microsoft claims
- Vista7 more secure than Linux and Mac OS X
- Conficker self updates, launches false infection alert
- SSH server attacks resurface
- Hacking Tools & Techniques and How to Protect Your Network from Them
- Microsoft Black Tuesday: Microsoft finally fixes Excel zero day, plus more
- Conficker self updates, launches false infection alert
- Conficker reprogrammed for new attack run
- Rogue security software a rising threat
- Further Windows 7 features revealed