Data Storage Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Information for Data Storage Professionals
Friday, September 3rd 
Home
Storage Hardware
Storage Software
Storage Networks
Storage Trends
Next-Gen Storage
Data Security
DST Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement
Network Security

Problems Reported with DNS Vulnerability Patch

Problems Reported with DNS Vulnerability Patch
July 30, 2008 1:51PM

Bookmark and Share
The Domain Name Security vulnerability is not being patched quickly. And some patches, such as those for BIND systems, are causing performance problems. Apple, Inc. is also drawing criticism for not releasing information about DNS patches for its Mac OS X server. PowerDNS users appear immune to the DNS vulnerability.


Reports from IT Relevant Products/Services directors and major IT suppliers indicate that the security hole in Internet Domain Name System servers is being patched -- but not everyone, nor every company, is responding quickly.

News of the flaw in some DNS servers was released to the public early this month and the details were leaked in the middle of the month, catching many server Relevant Products/Services administrators by surprise. The hope was that most servers could be patched and ready before the public became aware of the details. But as a result of the leak, many servers worldwide remain vulnerable to attack.

Although no hacker software has yet been discovered that exploits the vulnerability, the potential exists for hackers to spoof the servers that translate URLs such as www.yourbank.com to an illegitimate location. The flaw could allow malicious programmers to redirect requests for Web sites to bogus sites, potentially capturing personal data such as bank account information Relevant Products/Services and passwords to legitimate Web destinations.

Who Is Patched and Who Isn't

Most American Internet service providers have corrected the problem with the patch, but some have yet to fully fix the problem. There is no concrete number on the servers that are affected, but worldwide estimates are in the hundreds of thousands. Comcast, Verizon, Microsoft and Cisco Systems are a few corporations that have gone on record as completing the vulnerability patch.

According to some reports, PowerDNS, used by AOL and Deutsche Telekom, is immune from the flaw. Developed by a Dutch company of the same name, the software is open source. In a letter posted on the company's Web site, PowerDNS founder Bert Hubert says, "We're being approached from various angles about PowerDNS and the recently discovered DNS vulnerability. To clear up any possible confusion, I'd like to state that since 2006, PowerDNS has not been vulnerable for the issue reported ... In fact, we've been warning the DNS community against these kinds of problems since around that time [2006]. In fact, according to reports, Dan Kaminsky, a security expert, uncovered this flaw in February of 2008, triggering a secret meeting in Redmond, Washington."

Critics are accusing Apple of ignoring the vulnerability, since the company has not released any information on the status of patching its Mac OS X server. According to blogger Rich Mogull, "Apple has yet to patch this vulnerability, which affects both the desktop Mac OS X and the Mac OS X server."

Some observers are speculating that Apple's preoccupation with the iPhone 3G Relevant Products/Services launch this month caused them to drop the ball on the security issue. According to a report by IDC this year, Apple is the 10th largest server vendor worldwide.

A Slow Patch

Patches that have been applied are reportedly running into other problems.

Systems running the BIND (Berkeley Internet Name Domain) DNS software are experiencing performance problems. The highest-volume servers -- receiving tens of thousands of requests per second -- appear to be most affected by the patch.

Experts are advising IT directors to deploy the patch nonetheless, and wait for a fix that will both secure servers and restore performance.

Tell Us What You Think
Comment:

Name:

Advertisement



 Network Security
1. China Faces New PC Security Battle
2. Security Threats a Record, IBM Says
3. Private Modes Have Security Holes
4. Pentagon Warns of China Cyberthreat
5. Adobe Updates Reader and Acrobat


advertisement


 Most Popular Articles
1. Dell Buys Virtualization Storage Provider 3PAR
2. Patch Fixes SMB Attack That Could Come from Within
3. Intel Will Acquire McAfee To Secure Online Computing
4. Apple Issues iOS Patch To Block Hacker Bonanza
5. Microsoft's August Patches Will Keep IT Admins Busy

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  HP Wins 3PAR at $2.4B as Dell Quits
  Data Storage Advances Are Looming
  VMware Reinforces 'IT as a Service'
  Dell Ponders Matching HP 3PAR Bid
  Why Does Everyone Want 3Par?

 Technology Marketplace
Compliance
Stand out from other IS Professionals and increase your earning potential.®.
Manage limitless content today—read EMC’s 15-minute guide to ECM.
 
Data Storage
Isilon scale-out storage is simple. Simple is smart.
 
Digital Life
IT PROS: Receive $10 in rewards to complete a 15 min. survey.
 
Enterprise I.T.
Stand out from other IS Professionals and increase your earning potential.®.
IT PROS: Receive $10 in rewards to complete a 15 min survey.
 
Enterprise Software
Manage limitless content today—read EMC’s 15-minute guide to ECM.
 
Mobile Gadgets
White Paper The Motorola ES400: Desktop power in a pocket-sized device
 
Mobile Industry News
The Motorola ES400: Desktop power in a pocket-sized device.
 
Mobile Phones
The Motorola ES400: Desktop power in a pocket-sized device.
 
Navigation
Data Storage Today
Home/Top News | Storage Hardware | Storage Software | Storage Networks | Storage Trends | Next-Gen Storage | Data Security
DST Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 Data Storage Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.