|
A compromised server believes it's sending people to the authentic site. And if the bogus site is designed well enough, users don't know the difference, unless the site starts behaving weirdly. Some clues might come if a page, like a banking Web site, is usually protected with Secure Sockets Layer, or SSL, which verifies a site's owner and shows a padlock icon or a green address bar inside the Web browser. The padlocks in particular, however, are not always foolproof, because scammers can spoof them. Just how widespread the attacks have been is hard to tell. The evidence of tampering can disappear before an Internet provider even learns there's a problem. The patching of DNS servers has accelerated. Kaminsky said 84 percent of the servers he tested at the beginning of the process were vulnerable. That has dropped to around 31 percent. Still, Kaminsky said some administrators of computer networks might not patch their machines until they come under attack. Others didn't patch immediately because they had to spend days or weeks testing the repairs.
That was the case with AT&T, which said the breach affected just one of its servers, a machine that was scheduled to be taken off line anyway. AT&T says it has fixed the problem. More details about the vulnerability are expected to emerge Wednesday, when Kaminsky speaks at the Black Hat computer security conference in Las Vegas. The conference and its sister event, DefCon, draw researchers, government investigators and corporate executives eager to learn about new vulnerabilities and how to protect against them. "There might be one or two things that haven't leaked yet," Kaminsky said with a snicker. "No one should even think they know the subject of the talk." DNS attacks aren't new. But Kaminsky discovered a way to link together some widely known weaknesses in the system, so that an attack that would have taken hours or days can now take only seconds.
"Quite frankly, all the pieces of this have been staring us in the face for decades, and none of us saw it until Dan put it all together," said Paul Vixie, president of the Internet Systems Consortium, a nonprofit that publishes the software inside most of the world's DNS servers. "This is the mother lode all right, from the point of view of Internet criminals looking for easier access to other people's money and secrets."
[Associated
Press;
Copyright 2008 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.
News | Sports | Business | Rural Review | Teaching & Learning | Home and Family | Tourism | Obituaries
Community |
Perspectives
|
Law & Courts |
Leisure Time
|
Spiritual Life |
Health & Fitness |
Teen Scene
Calendar
|
Letters to the Editor