Data Storage Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Information for Data Storage Professionals
Tuesday, February 9th 
Home
Storage Hardware
Storage Software
Storage Networks
Storage Trends
Next-Gen Storage
Data Security
Data Management
DST Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement
Data Security

Problems Reported with DNS Vulnerability Patch

Problems Reported with DNS Vulnerability Patch
July 30, 2008 1:51PM

Bookmark and Share
The Domain Name Security vulnerability is not being patched quickly. And some patches, such as those for BIND systems, are causing performance problems. Apple, Inc. is also drawing criticism for not releasing information about DNS patches for its Mac OS X server. PowerDNS users appear immune to the DNS vulnerability.


Reports from IT Relevant Products/Services directors and major IT suppliers indicate that the security hole in Internet Domain Name System servers is being patched -- but not everyone, nor every company, is responding quickly.

News of the flaw in some DNS servers was released to the public early this month and the details were leaked in the middle of the month, catching many server Relevant Products/Services administrators by surprise. The hope was that most servers could be patched and ready before the public became aware of the details. But as a result of the leak, many servers worldwide remain vulnerable to attack.

Although no hacker software has yet been discovered that exploits the vulnerability, the potential exists for hackers to spoof the servers that translate URLs such as www.yourbank.com to an illegitimate location. The flaw could allow malicious programmers to redirect requests for Web sites to bogus sites, potentially capturing personal data Relevant Products/Services such as bank account information and passwords to legitimate Web destinations.

Who Is Patched and Who Isn't

Most American Internet service Relevant Products/Services providers have corrected the problem with the patch, but some have yet to fully fix the problem. There is no concrete number on the servers that are affected, but worldwide estimates are in the hundreds of thousands. Comcast, Verizon, Microsoft Relevant Products/Services and Cisco Systems are a few corporations that have gone on record as completing the vulnerability patch.

According to some reports, PowerDNS, used by AOL and Deutsche Telekom, is immune from the flaw. Developed by a Dutch company of the same name, the software is open source. In a letter posted on the company's Web site, PowerDNS founder Bert Hubert says, "We're being approached from various angles about PowerDNS and the recently discovered DNS vulnerability. To clear up any possible confusion, I'd like to state that since 2006, PowerDNS has not been vulnerable for the issue reported ... In fact, we've been warning the DNS community against these kinds of problems since around that time [2006]. In fact, according to reports, Dan Kaminsky, a security expert, uncovered this flaw in February of 2008, triggering a secret meeting in Redmond, Washington."

Critics are accusing Apple of ignoring the vulnerability, since the company has not released any information on the status of patching its Mac OS X server. According to blogger Rich Mogull, "Apple has yet to patch this vulnerability, which affects both the desktop Relevant Products/Services Mac OS X and the Mac OS X server."

Some observers are speculating that Apple's preoccupation with the iPhone 3G launch this month caused them to drop the ball on the security issue. According to a report by IDC this year, Apple is the 10th largest server vendor worldwide.

A Slow Patch

Patches that have been applied are reportedly running into other problems.

Systems running the BIND (Berkeley Internet Name Domain) DNS software are experiencing performance Relevant Products/Services problems. The highest-volume servers -- receiving tens of thousands of requests per second -- appear to be most affected by the patch.

Experts are advising IT directors to deploy the patch nonetheless, and wait for a fix that will both secure Relevant Products/Services servers and restore performance.

Advertisement



 Data Security
1. China Busted Hacker-Training Site
2. FBI Tackles Haiti-Relief Scams
3. Patch Tuesday Will Tie MS Record
4. Google Apps Controls Mobile Devices
5. Torrent Traps Used To Harvest Logins


advertisement


 Most Popular Articles
1. Facebook Users Can Get McAfee Virus Protection
2. Adobe, Oracle Make Up for Light MS Patch Tuesday
3. Zuckerberg's Comments Unleash Firestorm of Dissent
4. Clinton Raises Google Attacks To an International Issue
5. New Malware Exploits Vulnerability in Internet Explorer

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Google May Make Gmail More Social
  China Busted Hacker-Training Site
  IBM Power7 Server Takes on Big Load
  FBI Tackles Haiti-Relief Scams
  Patch Tuesday Will Tie MS Record

 Technology Marketplace
Compliance
Stand out from other IS Professionals and increase your earning potential.®).
 
Enterprise Hardware
Now is the best time to buy a new APC Smart-UPS!
HP ProLiant G6 Servers: Perform like a superstar, Save like an accountant www.hp.com
 
Enterprise I.T.
Learn how Microsoft server upgrades can create efficiencies
Stand out from other IS Professionals and increase your earning potential.®).
 
Hardware
Find out why now is the best time to buy a new APC Smart-UPS!
 
Microsoft/Windows
Read about how to add efficiencies with Microsoft Virtualization.
 
Network Security
AT&T Synaptic Compute as a Service. Boost your power on demand.
 
Mobile Enterprise Spotlight

Analysts See iPad Price Drop, with Some Cannibalization
Just weeks before Apple officially rolls out the iPad, financial analysts are making pricing predictions. But could the analysis itself hinder the initial demand for the pricey tablet computer?

Bar Codes Go Mobile, Get Hip Again
For decades, retailers have used patterns of black dots and lines to encode data onto products. Now, bar codes are gaining favor as an easy way for cell-phone users to view ads and other data instantly.

'Dead Simple, Dirt Cheap' JooJoo Tablet Shipping Soon
The JooJoo, a web-browsing tablet device that is the subject of a high-profile legal dispute, appears on track to reach buyers at the end of February, but the tablet scene has dramatically changed.

Advertisement
Enterprise Software Spotlight

Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.

SAP CEO Abruptly Resigns; Co-CEOs Will Take Over
Business-software maker SAP announced an abrupt strategic shift in the corporate suite with Léo Apotheker resigning as CEO, to be replaced by co-CEOs Bill McDermott (left) and Jim Hagemann Snabe (right).

Cybersecurity Vendors Look Hot in 2010
Tech-security companies are poised to become Wall Street darlings this year, thanks in part to Google's tiff with China, which reinforced an already positive outlook for major security vendors.

Advertisement
Navigation
Data Storage Today
Home/Top News | Storage Hardware | Storage Software | Storage Networks | Storage Trends | Next-Gen Storage | Data Security
Data Management | DST Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 Data Storage Today. All rights reserved. Article rating technology by Blogowogo.