Language Selection

English French German Italian Portuguese Spanish

Poisoned web poses risk to security

Filed under
Web

COMPUTER criminals are coming up with ever stealthier ways to make money. Rather than attack PCs or email inboxes, their latest trick is to subvert the very infrastructure of the internet, the domain name system (DNS) that routes all net traffic.

In doing so, they redirect internet users to bogus websites, where visitors could have their passwords and credit details stolen, be forced to download malicious software, or be directed to links to pay-per-click adverts.

This kind of attack is called DNS cache poisoning or polluting. It was first done by pranksters in the early years of the internet, but it had limited impact and security patches eliminated the problem.

Now new loopholes have opened and poisoning appears to be back. This time experts can't be sure how much damage it might do. "We see the combination of DNS poisoning with other hostile actions as having a serious impact," says Swa Frantzen, a Belgium-based volunteer member of the SANS Internet Storm Center. "I think it's going to slowly die out," says Joe Stewart of net security company Lurhq in Chicago.

Internet poisoning returned to the fore in early March, when DNS software provided by antivirus firm Symantec was found to have a bug that made poisoning possible. Weeks later, the SANS centre uncovered a second spate of poisonings, but this time it was due to a security loophole.

Companies can protect themselves by switching to BIND 9, which will not accept or pass on poisoned information. But Gerhard Eschelbeck of the internet security company Qualys in Redwood Shores, California, says the problem may not be over. "I would not rule anything out. There are other creative ways that attackers can find to poison the DNS," he says. And poisoning is a much bigger deal than it was in the early days, because hackers can now use the technique to introduce "malware" onto servers and PCs, says Frantzen.

Full Story.

More in Tux Machines

Ubuntu Touch OTA-14 Officially Released with Revamped Unity 8 Interface, Fixes

A few moments ago, we've been informed by Canonical's Lukasz Zemczak about the general availability of the long-anticipated Ubuntu Touch OTA-14 software update for Ubuntu Phone and Ubuntu Tablet devices. Read more Also: Ubuntu OTA-14 Released, Fixes A Number Of Bugs

Cloud convenience is killing the open source database

Open source has never been more important or, ironically, irrelevant. As developers increasingly embrace the cloud to shorten time to market, they're speeding past open source, making it even harder to build an open source business. After all, if open source were largely a way for developers to skirt legal and purchasing departments to get the software they needed when they needed it, the cloud ups that convenience to the nth degree. In Accel's annual business review, the vaunted venture capital firm writes: "'Product' is no longer just the bits of software, it's also how the software is sold, supported, and made successful." The cloud is changing the way all software is consumed, including open source. Read more

Why the operating system matters even more in 2017

Operating systems don't quite date back to the beginning of computing, but they go back far enough. Mainframe customers wrote the first ones in the late 1950s, with operating systems that we'd more clearly recognize as such today—including OS/360 from IBM and Unix from Bell Labs—following over the next couple of decades. Read more

OpenGov Partnership members mull open source policy

The Open Government Partnership (OGP) will suggest to its member governments to create a policy on open source. This week, a draft proposal is to be finalised at the OGP Global Summit in Paris. Read more