Language Selection

English French German Italian Portuguese Spanish

Poisoned web poses risk to security

Filed under
Web

COMPUTER criminals are coming up with ever stealthier ways to make money. Rather than attack PCs or email inboxes, their latest trick is to subvert the very infrastructure of the internet, the domain name system (DNS) that routes all net traffic.

In doing so, they redirect internet users to bogus websites, where visitors could have their passwords and credit details stolen, be forced to download malicious software, or be directed to links to pay-per-click adverts.

This kind of attack is called DNS cache poisoning or polluting. It was first done by pranksters in the early years of the internet, but it had limited impact and security patches eliminated the problem.

Now new loopholes have opened and poisoning appears to be back. This time experts can't be sure how much damage it might do. "We see the combination of DNS poisoning with other hostile actions as having a serious impact," says Swa Frantzen, a Belgium-based volunteer member of the SANS Internet Storm Center. "I think it's going to slowly die out," says Joe Stewart of net security company Lurhq in Chicago.

Internet poisoning returned to the fore in early March, when DNS software provided by antivirus firm Symantec was found to have a bug that made poisoning possible. Weeks later, the SANS centre uncovered a second spate of poisonings, but this time it was due to a security loophole.

Companies can protect themselves by switching to BIND 9, which will not accept or pass on poisoned information. But Gerhard Eschelbeck of the internet security company Qualys in Redwood Shores, California, says the problem may not be over. "I would not rule anything out. There are other creative ways that attackers can find to poison the DNS," he says. And poisoning is a much bigger deal than it was in the early days, because hackers can now use the technique to introduce "malware" onto servers and PCs, says Frantzen.

Full Story.

More in Tux Machines

CentOS Linux 7 and 6 Users Receive New Microcode Updates for Intel and AMD CPUs

CentOS Linux is an open-source, free, enterprise-class, and community-supported operating system based on and compatible with Red Hat Enterprise Linux. As such, it regularly receives new important security updates as soon as they are released upstream by Red Hat. About two weeks ago, CentOS Linux 7 and 6 users received kernel and microcode updates that mitigated the Meltdown and Spectre security vulnerabilities unearthed earlier this month. However, after some thorough testing, Red Hat discovered that these updated microcode firmware developed by Intel and AMD caused hardware issues. Read more

Google moves to Debian for in-house Linux desktop

Google has officially confirmed the company is shifting its in-house Linux desktop from the Ubuntu-based Goobuntu to a new Linux distro, the DebianTesting-based gLinux. Margarita Manterola, a Google Engineer, quietly announced Google would move from Ubuntu to Debian-testing for its desktop Linux at DebConf17 in a lightning talk. Manterola explained that Google was moving to gLinux, a rolling release based on Debian Testing. Read more

Android Support Removed from Intel Graphics Driver Debugging Tool for Linux

For those unfamiliar with intel-gpu-tools, it's a collection of tools for GNU/Linux distribution that allows the debugging the official Intel graphics driver for Intel GPUs. Tools include a GPU hang dumping program, performance microbenchmarks for regression testing the DRM, as well as a performance monitor. The latest release, intel-gpu-tools 1.21, adds quite a bunch of changes, including automatic loading of DRM modules when opening a DRM device, much-improved GPU quiescing code to more thoroughly flush pending work and old data, as well as production support for the Meson build system while automake is still kept around. Read more

Educational-Oriented Escuelas Linux 5.6 Distro Released with LibreOffice 6.0

Based on the latest release of the Ubuntu-based and Enlightenment-focused Bodhi Linux operating system, Escuelas Linux 5.6 is powered by the Linux 4.14.13 kernel, which includes patches against the Meltdown and Spectre security vulnerabilities, and comes with a bunch of up-to-date educational apps. These include the OnlyOffice 4.8.6 office suite (only for the 64-bit edition), Vivaldi 1.13, Chromium 63, Google Chrome 63, and Mozilla Firefox 57 "Quantum" web browsers, Geogebra 5.0.414 geometry, algebra, statistics, and calculus app, latest Adobe Flash Player 28 plugin, and the upcoming LibreOffice 6.0 open-source office suite. Read more