Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Engineers Warn Of Attacks On Internet Vulnerability
Agence France-Presse (excerpt) ^ | July 24, 2008

Posted on 07/24/2008 4:05:59 PM PDT by HAL9000

Excerpt -

SAN FRANCISCO (AFP)--Internet security researchers warned Thursday that hackers have caught on to a "critical" flaw that lets them control traffic on the Internet.

~ snip ~

"We are in a lot of trouble," said IOActive security specialist Dan Kaminsky, who stumbled upon the Domain Name System (DNS) vulnerability about six months ago and reached out to industry giants to collaborate on a solution.

"This attack is very good. This attack is being weaponized out in the field. Everyone needs to patch, please. This is a big deal."

~ snip ~


(Excerpt) Read more at nasdaq.com ...


TOPICS: Business/Economy; Crime/Corruption; News/Current Events; Technical
KEYWORDS: cachepoisoning; dns; internet; phishing; security; spoofing

1 posted on 07/24/2008 4:06:00 PM PDT by HAL9000
[ Post Reply | Private Reply | View Replies]

To: HAL9000

Perhaps an alternate network is needed.


2 posted on 07/24/2008 4:10:34 PM PDT by Brian S. Fitzgerald
[ Post Reply | Private Reply | To 1 | View Replies]

To: HAL9000

You don’t have to use your ISP’s nameservers if you don’t want to.

I am using the nameservers provided by Open DNS. I checked them with the DNS checker at doxpara.com, and they seem to be ok.

OpenDNS is here:

http://www.opendns.com/


3 posted on 07/24/2008 4:12:51 PM PDT by proxy_user
[ Post Reply | Private Reply | To 1 | View Replies]

To: KylaStarr; Cindy; StillProud2BeFree; nw_arizona_granny; Velveeta; Dolphy; appalachian_dweller; ...

ping


4 posted on 07/24/2008 4:27:43 PM PDT by Calpernia (Hunters Rangers - Raising the Bar of Integrity http://www.barofintegrity.us)
[ Post Reply | Private Reply | To 1 | View Replies]

To: HAL9000

This is more hype that threat. Yes, there are some DNS servers that have not yet patched their servers. But this is a shrinking number and those servers can be taken out of operation very quickly, fixed and then restored.

Further, individuals can and often do use other third party DNS servers so should a server be attacked, users can switch to other sources.


5 posted on 07/24/2008 4:29:07 PM PDT by taxcontrol
[ Post Reply | Private Reply | To 1 | View Replies]

To: proxy_user
Here's another one which has worked fine for me during the last 5 years. Treewalk Homepage
6 posted on 07/24/2008 4:44:25 PM PDT by An Old Man ("The limits of tyrants are prescribed by the endurance of those whom they suppress." Douglas)
[ Post Reply | Private Reply | To 3 | View Replies]

To: HAL9000

bump


7 posted on 07/24/2008 4:58:55 PM PDT by Mediocrates
[ Post Reply | Private Reply | To 1 | View Replies]

To: An Old Man

This seems to be an entirely different thing. It is a local caching DNS server, but you are still ultimately reliant on the correctness of your ISP’s DNS. All it does is cache the results locally.

With Open DNS, you are using Open DNS’s nameservers, not your ISP’s. You type the IP addresses they give you into your network configuration interface, and then you’re using their servers for all name lookups.


8 posted on 07/24/2008 5:59:53 PM PDT by proxy_user
[ Post Reply | Private Reply | To 6 | View Replies]

To: proxy_user
"All it does is cache the results locally."

You got it!
Whenever my cache needs to be refreshed, I use these servers to update it. That way I completely bypass the ISP.

Do you recognise the IP's?
208.67.222.222
208.67.220.220

9 posted on 07/24/2008 7:04:55 PM PDT by An Old Man ("The limits of tyrants are prescribed by the endurance of those whom they suppress." Douglas)
[ Post Reply | Private Reply | To 8 | View Replies]

To: An Old Man
Yes - I recognized them immediately - OpenDNS.

Here's the IP address of another DNS server for you: 4.2.2.1.

The DNS server at 4.2.2.1 is run by Level3, from Broomfield, Colorado. It's not the fastest or fanciest DNS server, but it makes a handy DNS alternative when one just has to type one in from memory. See Alternate DNS Servers or Where is 4.2.2.1 Located? for more information about 4.2.2.1.

10 posted on 07/24/2008 8:27:30 PM PDT by ThePythonicCow (By their false faith in Man as God, the left would destroy us. They call this faith change.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Calpernia

Thanks for the ping.........


11 posted on 07/25/2008 12:38:32 PM PDT by nw_arizona_granny ( http://www.freerepublic.com/focus/chat/1990507/posts?page=451 SURVIVAL, RECIPES, GARDENS, & INFO)
[ Post Reply | Private Reply | To 4 | View Replies]

To: HAL9000

This can’t be happening. Name servers don’t run Windows and are therefore immune to attacks of this kind.

Right?


12 posted on 07/25/2008 12:46:52 PM PDT by js1138
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson