28 Jul 2008
The first attacks to use the so-called Kaminsky DNS vulnerability have surfaced, according to reports.
A user named James Kosin sent details of the attack to a Fedora Linux mailing list.
Kosin posted a log which he said was gathered on the night of 24 July. The attack attempts to access the server cache for entries to such sites as MySpace, eBay and Wachovia.
The attack targets a vulnerability in the Domain Name System in which an attacker could alter the cache on a DNS server to redirect site requests to malicious third-party sites.
"The spooks are out in full on this security vulnerability. Patch or upgrade now," wrote Kosin.
Industry experts, including Kaminsky himself, have issued similar warnings to administrators. Kaminsky held off releasing the details of the flaw until vendors could release a patch.
Exploit code for the vulnerability was posted last week as a module for the Metasploit framework.
Experts believe that most major ISPs and vendors have patched the flaw, but poorly-maintained DNS servers could still be open to the attack.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Order Processing Specialist - 12 Month Fixed Term Contract...
Great opening with one of the worlds leading information...
JAVA J2EE Developer required with RIA, web services...
Hi, Job Title : Linux Admin Location : Brussels...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Not an attack
That client IP (143.215.143.11) points back to the Georgia Institute of Technology. Likely someone doing their own tests and not a phisher/spammer/attacker.
Posted by: Kevin 28 Jul 2008