The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft DNS bug long-known, familiar to researchers
Time: 00:23 EST/05:23 GMT | News Source: ComputerWorld | Posted By: Kenneth van Surksum

The DNS cache poisoning bug that Microsoft Corp. patched last Tuesday stems from a flaw that has been known to researchers for 10 years or more, the two security firms credited with reporting the vulnerability said this week.

Microsoft patched the Domain Name System (DNS) server included with Windows 2000 Server and Windows Server 2003 to fix what it called a spoofing flaw that could be exploited by identity thieves or malware authors to silently redirect users from intended Web destinations to malicious pretenders.

A day later, the two security companies that Microsoft acknowledged for independently reporting the bug -- Scanit NV/SA of Brussels, Belgium, and Trusteer Ltd. of Tel Aviv, Israel -- published their analysis. The problem, said Scanit and Trusteer, is that Windows DNS server generates predictable transaction IDs, the security identifiers meant to make spoofing and cache poisoning difficult to impossible. Because the transaction IDs can be predicted, hackers can deceive the name server into thinking that false DNS data is legitimate.

Write Comment
Return to News

  Displaying 576 through 576 of 576
Prev | First
  The time now is 6:36:58 PM ET.
Any comment problems? E-mail us
#576 By 4240821 (82.115.4.230) at 8/2/2025 8:22:07 AM
https://justpaste.me/dTQP5
https://justpaste.me/d0jw2
https://justpaste.me/fu3V2
https://justpaste.me/eWmT2
https://justpaste.me/fjUi4
https://justpaste.me/e8Be1
https://justpaste.me/bAD62
https://justpaste.me/dHAI2
https://justpaste.me/fOdU
https://justpaste.me/alSa4

Write Comment
Return to News
  Displaying 576 through 576 of 576
Prev | First
  The time now is 6:36:58 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *