Details of DNS bug posted by accident

Oops...I dropped the ball.

A computer security company inadvertently published details of a major DNS flaw several weeks before they were due to be disclosed.

The flaw was discovered several months ago by IOActive researcher Dan Kaminsky, who worked through the early part of this year with vendors such as Microsoft, Cisco and the Internet Systems Consortium to patch the issue.

The companies released a fix for the bug two weeks ago and encouraged corporate users and Internet service providers to patch their DNS systems as soon as possible. Although the problem could affect some home users, it is not considered to be a major issue for consumers, according to Kaminsky.

At the time he announced the flaw, Kaminsky asked members of the security research community to hold off on public speculation about its precise nature in order to give users time to patch their systems. Kaminsky had planned to disclose details of the flaw during a presentation at the Black Hat security conference set for 6 August.

Some researchers took the request as a personal challenge to find the flaw before Kaminsky's talk. Others complained at being kept in the dark about the technical details of his finding.

On Monday, Zynamics CEO Thomas Dullien (who uses the hacker name Halvar Flake) ttook a guess at the bug admitting that he knew very little about DNS.

His findings were quickly confirmed by Matasano Security, a vendor that had been briefed on the issue.

"The cat is out of the bag. Yes, Halvar Flake figured out the flaw Dan Kaminsky will announce at Black Hat," Matasano said in a blog posting that was removed within five minutes of its publication.

Matasano's post discusses the technical details of the bug, saying that by using a fast Internet connection, an attacker could launch what's known as a DNS cache poisoning attack against a Domain Name server and succeed, for example, in redirecting traffic to malicious websites within about 10 seconds.

Matasano Researcher Thomas Ptacek declined to comment on whether or not Flake had actually figured out the flaw, but said the item had been "accidentally posted too soon." Ptacek was one of the few security researchers who had been given a detailed briefing on the bug and had agreed not to comment on it before details were made public.

Matasano's post inadvertently confirmed that Flake had described the flaw correctly, Ptacek admitted.

Ptacek apologised to Kaminsky on his company blog. "We regret that it ran," he wrote. "We removed it from the blog as soon as we saw it. Unfortunately, it takes only seconds for Internet publications to spread."

Kaminsky's attack takes advantage of several known DNS bugs, combining them in a novel way, said Cricket Liu vice president of architecture with DNS appliance vendor Infoblox, after viewing the Matasano post.

The bug has to do with the way DNS clients and servers obtain information from other DNS servers on the Internet. When the DNS software does not know the numerical IP address of a computer, it asks another DNS server for this information. With cache poisoning, the attacker tricks the DNS software into believing that legitimate domains map to malicious IP addresses.

In Kaminsky's attack a cache poisoning attempt also includes what is known as "Additional Resource Record" data. By adding this data, the attack becomes much more powerful, security experts say. "The combination of them is pretty bad," Liu said.

An attacker could launch such an attack against an Internet service provider's domain name servers and then redirect them to malicious servers. By poisoning the domain name record for www.citibank.com, for example, the attackers could redirect the ISP's users to a malicious phishing server every time they tried to visit the banking site with their web browser.

Kaminsky declined to confirm that Flake had discovered his issue, but in a posting his own website he wrote "13>0," apparently a comment that the 13 days administrators have had to patch his flaw before its public disclosure is better than nothing.

"Patch. Today. Now. Yes, stay late," he wrote.

He has posted a test on his website that anyone can run to find our if their network's DNS software is patched


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Related Security news

Gumblar malware attack surges again

Malware hijacks Google searches to infect PCs

McAfee unveils Email and Web Security Appliance 5.5

Appliance integrates McAfee's cloud-based global threat intelligence

Google Apps adds Postini security software

Postini policy enforcement layer moves beyond Gmail

Microsoft left Windows 7 open to hackers, says Sophos

'Neutered' UAC misses 7 of 8 trojans



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Service-oriented security

SOA has become an integral part of enterprise software by providing a framework to efficiently develop software as services that is easily sharable, reusable, and integrated. No where is the need more apparent than in the Identity Management space. Welcome to the age of Service-Oriented Security (SOS).

Download Whitepaper

Data protection prospective vendor checklist

Organisations need a way to map business needs against all these challenges in procuring a technical solution. To help, SANS has developed the following Prospective Vendor Checklist.

Download Whitepaper

Best practices for optimising performance and availability in virtual infrastructures

Many IT administrators have already learned the hard way that managing the performance and availability of services built on virtualisation technologies can be difficult, if not impossible at times. All too often, early adopters of virtualisation have struggled with limited technology features and stability constraints, while learning new ways to effectively manage capacity requirements.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
BMC

Unlock the hidden IT opportunities in troubled economic times

How to take advantage of the growth potential that will occur when the economy rebounds
With the right approach, processes, and technology, it’s possible for IT to provide higher-quality services for a lower cost, while also empowering the business to position itself to take advantage of the growth potential that will occur when the economy rebounds.

Download white paper

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *