Hacker
The DNS flaw allows hackers to reroute information sent across the internet

DNS flaw causes security scramble

Cache poisoning workarounds published

Clement James

The well-publicised vulnerability in the DNS system, which can lead to DNS cache poisoning, has got security firms scrambling to provide protection.

Security service provider Integralis introduced a three-point system this week which it claims provides an immediate fix to eliminate the security risks and provide long-term protection.

Advertisement

The vulnerability allows a hacker to reroute information sent across the internet in such a way that existing security software and appliances may not detect a problem.

Once the routing has been changed the hackers can then extract any information transmitted. This can enable identity theft and major criminal activity on a personal and business basis.

DNS cache poisoning allows an attacker to introduce 'fake' DNS information into a caching name server.

Once 'poisoned' the DNS routing is changed to take legitimate URL requests and send them to a 'rogue' server which looks and acts like the actual server.

"Email and browser-based 'in the cloud' applications play a major part in day-to-day business transactions, so a security breach of this kind could have catastrophic business and personal implications," said Graham Jones, UK managing director at Integralis.

"Identity theft and business espionage are immediate threats, and stolen competitive information could be sold to the highest bidder."

Integralis explained that the quickest way to stop the security breach is to install a product that will use the root DNS servers and only trust authoritative name servers, thereby addressing the vulnerability for all email and internet traffic.

The second step is to work directly with security vendors to supply details of software patches available to close the security vulnerability.

Finally, an assessment of current security protection should be performed to help an organisation gain a good understanding of the information security issues it may have.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Further reading

DNS exploit haunts researcher

Local ISP attack affects BreakingPoint

Professor John Walker

US government security data compromised

DNS slip-up opens up CIA, FBI and DoD information

First DNS attacks reported

User reports cache-poisoning attempt

Exploit emerges for DNS flaw

First attack tool created for vulnerability

Related whitepapers

Related jobs

Most watched

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

old computer

Government honours veterans of Bletchley Park at last

Surviving veterans of the code-breaking facility to receive badge of...

Motorola MC55 Enterprise Digital Assistant

Review: Motorola MC55 Enterprise Digital Assistant

A rugged Windows Mobile device for mobile workers

BT

BT promises 1.5m fibre connections by summer 2010

Telco begins major rollout in 69 locations across the UK

Primary Navigation