Technology Review - Published By MIT
Advertisement

A Patch to Fix the Net

A major flaw in the design of the Internet is being repaired by a large group of vendors.

By Erica Naone

Thursday, July 10, 2008

smaller text tool iconmedium text tool iconlarger text tool icon

On Tuesday, major vendors released patches to address a flaw in the underpinnings of the Internet, in what researchers say is the largest synchronized security update in the history of the Web. Vendors and security researchers are hoping that their coordinated efforts will get the fix out to most of the systems that need it before attackers are able to identify the flaw and begin to exploit it. Attackers could use the flaw to control Internet traffic, potentially directing users to phishing sites or sites loaded with malicious software.

Credit: Technology Review

Discovered six months ago by security researcher Dan Kaminsky, director of penetration testing services at IOActive, the flaw is in the domain name system, a core element of the Web that helps systems connected to the Internet locate each other. Kaminsky likens the domain name system to the telephone company's 411 system. When a user types in a Web address--technologyreview.com--the domain name system matches it to the numerical address of the corresponding Web server--69.147.160.210. It's like giving a name to 411 and receiving a phone number, Kaminsky says.

The flaw that Kaminsky found could allow attackers to take control of the system and direct Internet traffic wherever they want it to go. The worst-case scenario, he says, could look pretty bleak. "You'd have the Internet, but it wouldn't be the Internet you expect," Kaminsky says. A user might type in the address for the Bank of America website, for example, and be redirected to a phishing site created by an attacker.

Story continues below


Details of the flaw are being kept secret for now. After Kaminsky discovered it, he quietly notified the major vendors of hardware and software for domain name servers. In March, he was one of 16 researchers who met at Microsoft's Redmond, WA, campus to plan how to deal with the flaw without releasing information that could help attackers. The researchers began working with vendors to release patches simultaneously. Also, since patches are known for giving away information that can help attackers reverse-engineer malicious software, the researchers chose a fix that kept the exact nature of the problem hidden. "We've done everything in our power up to and including selecting an obscure fix to provide the good guys with as much of an advantage as possible," Kaminsky says. "The advantage won't last forever. We think--we hope--it'll last a month."

Since the flaw is in the design of the domain name system itself, it afflicts products made by a variety of vendors, including Microsoft, Cisco, Sun Microsystems, and Red Hat, according to a report released by the U.S. Department of Homeland Security's Computer Emergency Readiness Team. The flaw also poses more problems for servers than it does for Web surfers, so vendors are focusing on getting patches to Internet service providers and company networks that might be vulnerable. Most home users will be covered by automatic updates to their operating systems.

Comments

  • Congraulations
    A team of companies working together to resolve a computer breach and resolving it quietly before it could be mass exploited....great effort and many thanks!
    Rate this comment: 12345

    rocketscienc...
    07/10/2008
    Posts:6
    Avg Rating:
    4/5
  • return to sender
    Internet worms, viruses, malicious software, netbots, spiders. It's a veritable jungle out there.
    Rate this comment: 12345

    phoenix
    07/10/2008
    Posts:172
    Avg Rating:
    3/5
  • A short
    I am interested to see the details of this vulnerability to see how much they are blowing this out of proportion.

    For the record the confirmation code is most likely a short which is 65536.
    Rate this comment: 12345

    zig158
    07/12/2008
    Posts:64
    Avg Rating:
    4/5
  • comcast
    I think this exploite was allready used to re-direct the comcast e-mail login page about 2 weeks ago.
    Rate this comment: 12345

    mightybob
    07/12/2008
    Posts:9
    Avg Rating:
    3/5

Log In

Forgot your password?     Register »
Advertisement

Videos

The Marcellus Shale Gas Rush
Technology Review November/December 2009

Current Issue

Natural Gas Changes the Energy Map
The United States has vast supplies of this cleaner fossil fuel. But how should we use it?
Featured Content
Sponsored by:
White Papers

Twelve ways to reduce costs with SQL Server 2008
Find out how to reduce costs and get more efficient

Download

Total Economic Impact of SQL Server 2008 Upgrade
Forrester reports on increasing productivity and management capabilities

Download 

Achieving Cost and Resource Savings with UC
How Office Communications Server R2 and Exchange Server can make your business smarter and more efficient

Download 

The Compelling Case for Conferencing
Read how you can improve workload support and find IT efficiencies

Download

How Windows Server 2008 R2 Helps Optimize IT and Save you Money
Read how you can improve workload support and find IT efficiencies

Download

Windows Server 2008 R2 Hyper-V Live Migration
See how Windows Server 2008 R2 and Hyper-V enable virtualization and Live Migration

Download
Advertisement
Subscribe to Technology Review's daily e-mail update. Enter your e-mail address

TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.