IETF: Should We Ignore The Kaminsky DNS Bug?
Carolyn Duffy Marsan writes on NetworkWorld:
The Internet engineering community is grappling with what to do about a serious flaw in the DNS discovered this summer, and the ongoing debate brings to mind a famous quotation from Voltaire: "The perfect is the enemy of the good."
At issue is whether the group should use its resources to encourage DNS registries, ISPs and enterprises to upgrade to the ultimate DNS security solution known as DNSSEC; or whether it should tweak the DNS protocols to address the so-called Kaminsky bug as an interim step. The issue is being debated at a meeting of the IETF, the Internet's leading standards body, being held here [Minneapolis] this week.
More
here.
Black Hat: Kaminsky: Many Ways to Attack DNS
Robert McMillan writes on ComputerWorld:
There were 6 a.m. calls from Finnish certificate authorities and also some pretty harsh words from his peers in the security community -- even an accidentally leaked Black Hat presentation. But after managing the response to one of the most highly publicized Internet flaws in recent memory, Dan Kaminsky said Wednesday that he'd do it all over again.
Kaminsky's full-time job over the past few months has been working with software vendors and Internet companies to fix a widespread flaw in the DNS (domain name system) used by computers to find each other on the Internet. Kaminsky, in conjunction with an assortment of pre-alerted tech vendors and experts, first disclosed the problem on July 8, warning corporate users and Internet service providers to patch their software as quickly as possible.
On Wednesday, he disclosed more details of the issue during a crowded session at the Black Hat conference, describing a dizzying array of attacks that could exploit DNS. Kaminsky also talked about some of the work he'd done to fix critical Internet services that could also be hit with this attack.
More
here.
DNS Exploit in the Wild
Kim Zetter writes on Threat Level:
Well it took a little longer than expected so it's not quite a zero-day exploit, but the anticipated attack code to exploit the critical Kaminsky DNS cache-poisoning flaw is now in the wild (assuming there wasn't one already out there).
Let's call it a .5-day exploit.
HD Moore, creator of the Metasploit Framework research and hacking tool, pinged me that he's just released the code. System administrators who dragged their feet over updating their DNS servers have lost the race . . . so to speak. But that doesn't mean it's too late to patch your system.
More
here.
Kaminsky (Finally) Provides DNS Flaw Details
Robert Vamosi writes on C|Net News:
In his first public comments since his Domain Name System (DNS) cache poisoning flaw was made public, Dan Kaminsky said in a conference call on Thursday he doesn't want to parse who said what when. He just wants everyone to understand that they must patch their systems now.
Speaking during the second pre-Black Hat security conference Webinar, Kaminsky, who's director of penetration testing for IOActive, provided the most information to date about the DNS flaw he found earlier this year but only disclosed in public on July 8.
More
here.
DNSstuff Freeware Detects Vulnerable DNS Servers
Brian Prince writes on eWeek:
DNSstuff.com is offering a free tool for organizations looking to test the susceptibility of their domain name servers to a fundamental flaw in the Domain Name System (DNS) protocol revealed publicly last week.
A provider of on-demand DNS and network analysis tools, DNSstuff made the freeware, which company officials have dubbed DNS Vulnerability Check, available on its site Wednesday. The tool is meant to test for the vulnerability reported by Dan Kaminsky, director of penetration testing for IOActive.
The researcher reportedly uncovered a flaw in the DNS protocol that can be exploited to poison DNS server caches and re-direct Internet traffic. While he has publicly kept details of the vulnerability close to his vest, several vendors coordinated the release of a patch in response.
More
here.
Massive, Coordinated DNS Patch Released
Robert Vamosi writes on the C|Net "D3F3NS3 1N D3PTH" Blog:
A security researcher has responsibly disclosed a fundamental flaw within the Domain Name System (DNS), the addressing scheme behind the common names used on the Internet. Currently, it may be possible to guess these transaction ID values in advance and assert a malicious server as the authoritative DNS server for a popular bank or e-commerce site. The news was announced Tuesday.
Dan Kaminsky, director of penetration testing services for IO Active, found the DNS flaw earlier this year. Rather than sell the vulnerability, as some researchers have done, Kaminsky decided instead to gather the affected parties and discuss it with them first. Without disclosing any technical details, he said, "the severity is shown by the number of people who've gotten onboard with this patch."
He declined to name the flaw as that would give away details.
More
here.
Valuable Lesson Emerges From DNS Flaw Handling
Dennis Fisher writes on Search Security:
Let us now praise the efforts of noble men. Dan Kaminsky, Paul Vixie, CERT and nameless dozens of engineers and admins at ISPs and backbone providers around the world did a tremendous job pulling together a massive, coordinated response to the DNS vulnerability Kaminsky found recently. The kind of big, distributed effort that was required to mitigate this threat is a rare thing indeed.
The right people were notified quietly, the problem was explained, a fix was devised and the patch was applied in all the critical spots in an astonishingly short amount of time. And while Kaminsky took heat for overhyping the severity of the problem in the hopes of pumping up the attendance at his Black Hat talk, other researchers who had been briefed on the problem came forward and said, Look, this is a serious problem. Go patch. Right now. It looked like everything had worked smoothly and the furor was starting to die down as the community waited for Kaminsky to release the gory details next month.
And then in the space of a few hours on Monday, all hell broke loose.
More
here.
One in Four DNS Servers Unpatched for Kaminsky Security Flaw, Study Finds
Brian Prince writes on eWeek:
New research offers a peak into the state of security of domain name server security β and itβs not all pleasing to the eye.
In an annual study of domain name servers (DNS) connected to the Internet by The Measurement Factory, it was uncovered that roughly one in four DNS servers does not perform source port randomization, despite the publicity surrounding the DNS vulnerability reported by security researcher Dan Kaminsky earlier this year.
The study, which was sponsored by Infoblox, also found that more than 40 percent of Internet name servers allow recursive queries. With the study estimating 11.9 million name servers are reachable from the Internet, the percentages means millions of name servers may be open to cache poisoning and distributed denial of service attacks.
More
here.
DNS servers--an Internet Achilles' heel
Joris Evers writes in C|Net News:
Hundreds of thousands of Internet servers are at risk of an attack that would redirect unknowing Web surfers from legitimate sites to malicious ones.
In a scan of 2.5 million so-called Domain Name System machines, which act as the White Pages of the Internet, security researcher Dan Kaminsky found that about 230,000 are potentially vulnerable to a threat known as DNS cache poisoning.
"That is almost 10 percent of the scanned DNS servers," Kaminsky said in a presentation last week at the Black Hat security event in Las Vegas. "If you are not auditing your DNS servers, please start," he said.
The motivation for a potential attack is money, according to the SANS Internet Storm Center, which tracks network threats. Attackers typically get paid for each spyware or adware program they manage to get installed on a person's PC.
Black Hat: Web Browser Attack Skirts Corporate Firewalls - UPDATE
Robert McMillan writes on CIO.com:
A 10-year-old security problem has come back to haunt corporate IT, a security researcher told an audience at the Black Hat conference in Las Vegas Wednesday.
Dan Kaminsky, director of penetration testing for IO Active, showed how problems in the way browser software works with the Internet's domain name system could be exploited to give attackers access to any resources behind the corporate firewall.
He described a multi-step attack that could be used to scan corporate networks for data or vulnerabilities. But at the heart of the attack is a 1996 paper by Princeton researchers showing how a Java applet could be used to access systems on a victim's network. "It's one of the few things that's actually come back from the dead," Kaminsky said.
The fundamental problem, according to Kaminsky, is in the way that Web browser software decides how to trust other computers. This decision is based on the Internet domain name of the computer, and that DNS information can be misused, Kaminsky said. "It's a binding problem," he said during an interview after his talk. "They assume a value is not changing, but the attacker can change it whenever he chooses."
More
here.
UPDATE: 7 August 2007 11:00 PDT: Lisa Vaas has really nice write-up of the mecahnics of this
here on eWeek.
Black Hat Webcast With Dan Kaminsky is Now Online
Via blackhat.com.
Our second webcast was very well attended and full of great information from Kaminsky about the DNS Vulnerability that's all over the news these days. If you weren't able to make it to the live event, you can catch up now online.
To view a synced online replay, follow this link.
To download the mp3, follow this link.
More
here.
BGP: The Internet's Biggest Security Hole
Kim Zetter writes on Threat Level:
Two security researchers have demonstrated a new technique to stealthily intercept internet traffic on a scale previously presumed to be unavailable to anyone outside of intelligence agencies like the National Security Agency.
The tactic exploits the internet routing protocol BGP (Border Gateway Protocol) to let an attacker surreptitiously monitor unencrypted internet traffic anywhere in the world, and even modify it before it reaches its destination.
The demonstration is only the latest attack to highlight fundamental security weaknesses in some of the internet's core protocols. Those protocols were largely developed in the 1970s with the assumption that every node on the then-nascent network would be trustworthy. The world was reminded of the quaintness of that assumption in July, when researcher Dan Kaminsky disclosed a serious vulnerability in the DNS system. Experts say the new demonstration targets a potentially larger weakness.
The man-in-the-middle attack exploits BGP to fool routers into re-directing data to an eavesdropper's network.
Anyone with a BGP router (ISPs, large corporations or anyone with space at a carrier hotel) could intercept data headed to a target IP address or group of addresses. The attack intercepts only traffic headed to target addresses, not from them, and it can't always vacuum in traffic within a network -- say, from one AT&T customer to another.
More
here and
here.
VeriSign and ICANN Square Off Over the DNS Root
Ryan Singel writes on Threat Level:
The internet has a huge security problem that's temporarily fixed with bent paperclips and some gaffer's tape. Without concerted effort, hackers could easily spoil what little confidence remains in the internet.
In fact, cyber-criminals are already exploiting the Domain Name System hack uncovered by security researcher Dan Kaminsky this summer -β essentially setting up fake banking websites that users reach by typing in their bank's real domain name. (That's according to research by Georgia Tech's David Dagon and Internet System Consortium's Paul Vixie.)
That's why the U.S. government finally put out a call Thursday [Actually, it was Wednesday. - ferg] for comments on whether the net as a whole should adopt new security protocols called DNSSEC, and asking who should have the privilege of controlling the master keys.
Two longstanding net infrastructure rivals -- ICANN and VeriSign -β each want the job.
Internet experts are siding overwhelmingly with ICANN, arguing that the crucial responsibility of making sure users can trust the technical equivalent of the internet's phone book belongs in the hands of the net's main oversight body.
More
here.
2008 Pwnie Award Winners
Via The 2008 Pwnie Award Page.
- Best Server-Side Bug: Ryan Smith and Alex Wheeler (Windows IGMP kernel vulnerability discovery)
- Best Client-Side Bug: Nate McFeters, Rob Carter, and Billy Rios (Multiple URL protocol handling flaws)
- Mass 0wnage: For the mass of Wordpress vulnerabilities found this past year (and anyone who found them)
- Most Innovative Research: Cold Boot attacks on disk encryption keys (Princeton researchers)
- Lamest Vendor Response: McAfee, for its reaction to the over 60 Websites classified as "Hacker Safe" by its ScanAlert service that were found to be XSS-vulnerable -- including the ScanAlert Website itself.
- Most Overhyped Bug: Dan Kaminsky's Unspecified DNS cache poisoning vulnerability.
- Best Song: "Packing the K!" Kaspersky Lab
- Most Epic FAIL: Debian, for shipping a backdoored OpenSSL library for two years
- Lifetime Achievement Award: Tim Newsham
More
here.