Free Republic
Browse · Search
News/Activism
Topics · Post Article

Most of you techies have already patched(right??), if not....well, heck, until all the TLD and ISP's prominent DNS servers are patched worldwide....

Kaminsky's Powerpoints used yesterday at the convention found here:

Black-Hat-2008-Dan-Kaminsky-releases-dns-info

104 Slides in all.

Check to see whether you/yourISP needs patching here:

DoxPara

1 posted on 08/07/2008 12:14:03 PM PDT by Freemeorkillme
[ Post Reply | Private Reply | View Replies ]


To: ShadowAce

.


2 posted on 08/07/2008 12:18:57 PM PDT by KoRn (CTHULHU '08 - I won't settle for a lesser evil any longer!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Freemeorkillme

A little aside, DNSRake (a tool he used but didn’t demo) poisons cache within 10 second.

There are obviously other tools out there(Metaspoit, et al), but he used this tool in his proof of exploit presentation.


3 posted on 08/07/2008 12:19:58 PM PDT by Freemeorkillme
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Freemeorkillme; rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ..

5 posted on 08/07/2008 12:33:19 PM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Freemeorkillme
"So being able to alter the associations between domain names and IP addresses allows malicious attackers to control where online information gets routed. "

I am no geek. I use the web a lot and notice stuff.

Yesterday at one of my favorite sources for FR http://www.telegraph.co.uk/news/index.jhtml, "Business", first IE tells me it can't open the window. When I refreshed the URL, I went to Walmart.com.

Is this what is being referred to in the article. Is it happening already?

yitbos

6 posted on 08/07/2008 12:57:03 PM PDT by bruinbirdman ("Those who control language control minds." - Ayn Rand)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Freemeorkillme
Grrrr.

This is NOT a DNS flaw.

This is a flaw in BIND, a particular piece of software that does DNS.

While the majority of DNS servers use BIND, it is not the only one.

I stopped using BIND many years ago due to it's poor track record of security and compliance with RFCs.

I switched to DJBDNS and have had zero problems with DNS since then.

12 posted on 08/07/2008 1:29:26 PM PDT by Knitebane (Happily Microsoft free since 1999.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Freemeorkillme

B4L8r


17 posted on 08/07/2008 1:39:07 PM PDT by AFreeBird
[ Post Reply | Private Reply | To 1 | View Replies ]

To: LonePalm; LambChop_NY
Self Ping for later.

Garde la Foi, mes amis! Nous nous sommes les sauveurs de la République! Maintenant et Toujours!
(Keep the Faith, my friends! We are the saviors of the Republic! Now and Forever!)

LonePalm, le Républicain du verre cassé (The Broken Glass Republican)

27 posted on 08/08/2008 7:54:56 AM PDT by LonePalm (Commander and Chef)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson