Microsoft Patches Major DNS Bug, The Fix Interferes With Firewalls
By Alice Turner
20:55, July 9th 2008
46 votes
Vote this story
Microsoft Patches Major DNS Bug, The Fix Interferes With Firewalls

Microsoft released four patches Tuesday, one of which addresses a major DNS spoofing flaw exploited by malware. It's unclear why it was labeled "important" and not "critical", even though the two privately reported vulnerabilities in the Windows Domain Name System (DNS) enabled a remote attacker to redirect network traffic intended for systems on the Internet to another address, usually the attacker’s own systems.

Microsoft found a way around the flaw by using strongly random DNS transaction IDs, using random sockets for UDP queries, and updating the logic used to manage the DNS cache, the company's security bulletin MS08-037 reads. However, Microsoft is not the only company affected by the DNS flaw. Most of networking companies need to also solve this bug, including Cisco, the Internet Software Consortium, Juniper Networks, Microsoft, Nominum, Red Hat and Sun. Other companies which might need to address the issue are Akamai, Apple, Debian/GNU Linux, Fedora, FreeBSD, Gentoo, HP, IBM, Motorola, Nokia and Ubuntu.

However, Microsoft's fix interferes with software firewalls for Windows, because they are not coded to support the newly implemented security measures, which include the randomization of several source ports. The DNS flaw was apparently discovered by Dan Kaminsky of the Seattle-based security firm IOActive Inc.

The issue points out that the current Domain Name System (DNS) is outdated, and switching to the newer Domain Name System Security Extensions (DNSSEC) is imperative. While DNS provides various information associated with domain names, primarily returning the IP address of a certain hostname, DNSSEC does this in a different way, because answers in DNSSEC are digitally signed.

Deploying DNSSEC at the root level of the Internet Domain System will prevent many spam and spoof attacks and force Internet crooks to find other means of attacking users.

Patch Tuesday also saw another three vulnerabilities fixed. The most prominent of the remaining three patches is the one affecting Windows Vista and Windows Vista Service Pack 1, as well as Windows Server 2008. The code injection flaw it fixes enables remote code execution through a code injection flaw. This is the common way of attack for malware. The flaw was not tagged as critical, apparently because it doesn't work without the user first taking some extra actions or adding special software or drivers.

Of the remaining two, one targets the Microsoft SQL Server and one Microsoft Exchange Server.



© 2007 - 2008 - eFluxMedia
Tags: DNS, DNSSEC, patch
dotclear

Other News in

No More Free Communication over the Phone for Barack Obama

No More Free Communication over the Phone for Barack Obama

Verizon Wireless admitted late Thursday that several of its employees broke company rules by accessing and viewing President-elect Barack Obama's personal cell phone account. The company’s president...

Enhanced iPhone Experience With The Latest Upgrade

Enhanced iPhone Experience With The Latest Upgrade

Apple has released a software upgrade for the iPhone 3G and iPod Touch that adds new features and fixes some stability bugs. Apple users were caught by surprise as the update appeared on Friday when...

Urine and Sweat Recycling System, Soon At The International Space Station

<!-- /* Style Definitions */ p.MsoNormal, li.MsoNormal,...

Apple Releases 2.2 Update For The iPhone

Apple Releases 2.2 Update For The iPhone

Early Friday, Apple Incorporated released their latest software update for the iPhone, the 2.2 one, which offers a series of new features to the smartphone’s users. These include Google Street...

Google Adds Editing Search Results Feature: SearchWiki

Google Adds Editing Search Results Feature: SearchWiki

Recently, search giant Google has introduced a new feature that enables Internet users to personalize their queries, called SearchWiki. The latter allows people to alter the order of, remove or add...

dotclear
Latest videos in Technology
Google Mobile App for iPhone,...
Google SearchWiki
Previewing LA Auto Show
Yahoo CEO to resign
A 'social mobile' for the...

dotclear
Technology You are here: Technology
» Technology   » Gadgets   » Video Games   
E-mail To A Friend Print RSS Text size: Decrease font size Increase font size
dotclear
dotclear
dotclear
Most Popular in Technology
Judge Dismisses Psystar’s Countersuit Claims As UngroundedJudge Dismisses Psystar’s Countersuit Claims As Ungrounded

» read full story
dotclear

Interested In This Topic?

News Alert will keep you informed. Find out more.
dotclear
Photos Gallery
dotclear
Today's Latest News
No More Free Communication over the Phone for Barack ObamaNo More Free Communication over the Phone for Barack Obama

» read full story
dotclear