NEWS.com.au Network
NEWS.com.au |
FOX SPORTS |
CLASSIFIEDS |
MOBILE |
Beijing Olympics
previous pause next Network Highlights:

New flaw could let hackers control web

Glenn Chapman in San Francisco | July 09, 2008

COMPUTER industry heavyweights are hustling to fix a flaw in the foundation of the internet that would let hackers control traffic on the web.

Security researcher Dan Kaminsky of IOActive stumbled upon the Domain Name System (DNS) vulnerability about six months ago and reached out to industry giants including Microsoft, Sun and Cisco to collaborate on a solution.

DNS is used by every computer that links to the internet and works similar to a telephone system routing calls to proper numbers, in this case the online numerical addresses of websites.

These software and hardware makers worked in secret for months to create a software patch released yesterday to repair the problem, which is in the way computers are routed to web page addresses.

The flaw would be a boon for "phishing" cons that involve leading people to imitation web pages of businesses such as bank or credit card companies to trick them into disclosing account numbers, passwords and other information.

Attackers could use the vulnerability to route internet users wherever they wanted no matter what website address is typed into a web browser.

"People should be concerned but they should not be panicking," Mr Kaminsky said. "We have bought you as much time as possible to test and apply the patch. Something of this scale has not happened before."

Mr Kaminsky built a web page, http://www.doxpara.com/, where people can find out whether their computers have the DNS vulnerability.

Mr Kaminsky was among about 16 researchers from around the world who met in March at Microsoft's campus in Redmond, Washington to figure out what to do about the flaw.

"I found it completely by accident," Mr Kaminsky said. "I was looking at something that had nothing to do with security. This one issue affected not just Microsoft and Cisco, but everybody."

The cadre of software wizards charted an unprecedented course, creating a patch to release simultaneously across all computer software platforms.

"This hasn't been done before and it is a massive undertaking," Mr Kaminsky said.

"A lot of people really stepped up and showed how collaboration can protect customers."

Automated updating should protect most personal computers. Microsoft released the fix in a software update package yesterday.

A push is on to make sure company networks and internet service providers make certain their computer servers are impervious to web traffic hijackings using the DNS attack.

The patch can't be "reverse engineered" by hackers interested in figuring out how to take advantage of the flaw, technical details of which are being kept secret for a month to give companies time to update computers.

"It's a very fundamental issue with how the entire addressing scheme of the internet works," Securosis analyst Rich Mogul said. "You'd have the internet, but it wouldn't be the internet you expect. (Hackers) would control everything."

"This is a pretty important day," said Jeff Moss, founder of a premier Black Hat computer security conference held annually in Las Vegas.

"We are seeing a massive multi-vendor patch for the entire addressing scheme for the internet - the kind of a flaw that would let someone trying to go to Google.com be directed to whereever an attacker wanted."

AFP

Story Tools

Share This Article

From here you can use the Social Web links to save New flaw could let hackers control web to a social bookmarking site.

Email To A Friend

* Required fields

Information provided on this page will not be used for any other purpose than to notify the recipient of the article you have chosen.

Register now!

Sign up for a daily update of the biggest stories in IT. From Microsoft to Microformats, you'll be on top of all the latest in IT news five days a week.

Also in Australian IT

Crisis may threaten tech firms

SMALL technology firms may collapse and inventions be lost overseas because research commercialisation faces such uncertainty and turmoil on several fronts, leading industry figures have warned.

Hard times ahead for hardware

CUTBACKS caused by the global financial crisis will affect some sectors heavily, Gartner research shows.

Chumby content lets it down

THE Chumby is a cute Gen Y digi-toy, an expensive, glorified alarm clock, or an example of the future of consumer computer devices.

Telstra best suited for NBN build

TELSTRA'S plan to build the National Broadband Network is predicated on us continuing to be a fully integrated company.

Also in the Australian

Jury finds Wood guilty of Byrne murder

10:19am THIRTEEN years after the body of model Caroline Byrne was found at the bottom of The Gap, her boyfriend is convicted of her murder.

Stocks fall 3pc, oil sector hit worst

LOCAL stocks tumbled in a global rout, pushing markets to bet on interest rates falling up to 125 basis points next month.

Film industry takes on net

AUSTRALIA'S biggest film and TV groups have ignited a long-simmering war with the internet sector.

Protest over more uni job cuts

INDUSTRIAL unrest at Victorian unis is set to worsen after La Trobe warned staff that voluntary job cuts weren't meeting targets.