Language Selection

English French German Italian Portuguese Spanish

Poisoned web poses risk to security

Filed under
Web

COMPUTER criminals are coming up with ever stealthier ways to make money. Rather than attack PCs or email inboxes, their latest trick is to subvert the very infrastructure of the internet, the domain name system (DNS) that routes all net traffic.

In doing so, they redirect internet users to bogus websites, where visitors could have their passwords and credit details stolen, be forced to download malicious software, or be directed to links to pay-per-click adverts.

This kind of attack is called DNS cache poisoning or polluting. It was first done by pranksters in the early years of the internet, but it had limited impact and security patches eliminated the problem.

Now new loopholes have opened and poisoning appears to be back. This time experts can't be sure how much damage it might do. "We see the combination of DNS poisoning with other hostile actions as having a serious impact," says Swa Frantzen, a Belgium-based volunteer member of the SANS Internet Storm Center. "I think it's going to slowly die out," says Joe Stewart of net security company Lurhq in Chicago.

Internet poisoning returned to the fore in early March, when DNS software provided by antivirus firm Symantec was found to have a bug that made poisoning possible. Weeks later, the SANS centre uncovered a second spate of poisonings, but this time it was due to a security loophole.

Companies can protect themselves by switching to BIND 9, which will not accept or pass on poisoned information. But Gerhard Eschelbeck of the internet security company Qualys in Redwood Shores, California, says the problem may not be over. "I would not rule anything out. There are other creative ways that attackers can find to poison the DNS," he says. And poisoning is a much bigger deal than it was in the early days, because hackers can now use the technique to introduce "malware" onto servers and PCs, says Frantzen.

Full Story.

More in Tux Machines

Xine Media Player Review – Powerful but Outdated

Xine is both an open source multimedia playback engine and a video playback application that's been around for a very long time. The number of people using this application has diminished, and there are few maintained third-party apps that are based on this engine. We'll take a closer look at the application to see why this is happening. Read more

Wine Announcement

The Wine development release 1.7.30 is now available. What's new in this release (see below for details): - More support for fonts in DirectWrite. - Improved ATL thunk support. - A few more C runtime functions. - Regedit import/export fixes. - Various bug fixes. Read more

CoreOS offers private Docker container registries for world+dog

Container-loving Linux vendor CoreOS has made its on-premises Docker container registry software available as a standalone product. Previously, CoreOS Enterprise Registry was only available as part of the company's Premium Managed Linux offering, which it describes as "OS as a service." As of Thursday, it is now available for use with any Docker-enabled OS – and these days, what Linux distro hasn't gone gaga for Docker? Even Microsoft is getting into the act. Read more

Manjaro Works To Make Calamares A Distribution-Independent Installer

The Arch-based Manjaro crew has been developing Calamares, an open-source installation framework they hope will basically lead to being a universal Linux distribution installer. The Manjaro camp has been developing Calamares as a distribution installer framework they'll be using for Manjaro 0.9+ and they also hope other Linux distributions will adopt it so it can become somewhat of a universal Linux installer so each distribution camp no longer keeps needing to write their own installer. Read more