The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft DNS bug long-known, familiar to researchers
Time: 00:23 EST/05:23 GMT | News Source: ComputerWorld | Posted By: Kenneth van Surksum

The DNS cache poisoning bug that Microsoft Corp. patched last Tuesday stems from a flaw that has been known to researchers for 10 years or more, the two security firms credited with reporting the vulnerability said this week.

Microsoft patched the Domain Name System (DNS) server included with Windows 2000 Server and Windows Server 2003 to fix what it called a spoofing flaw that could be exploited by identity thieves or malware authors to silently redirect users from intended Web destinations to malicious pretenders.

A day later, the two security companies that Microsoft acknowledged for independently reporting the bug -- Scanit NV/SA of Brussels, Belgium, and Trusteer Ltd. of Tel Aviv, Israel -- published their analysis. The problem, said Scanit and Trusteer, is that Windows DNS server generates predictable transaction IDs, the security identifiers meant to make spoofing and cache poisoning difficult to impossible. Because the transaction IDs can be predicted, hackers can deceive the name server into thinking that false DNS data is legitimate.

Write Comment
Return to News

  Displaying 201 through 201 of 201
Prev | First
  The time now is 7:33:52 PM ET.
Any comment problems? E-mail us
#201 By 4240821 (195.208.3.68) at 10/5/2024 2:37:21 PM
https://bio.site/tigpumanor429
https://bio.site/mondpunwojsve991
https://bio.site/bharkingminscer542
https://bio.site/hartknowunef803
https://bio.site/justhurdsandnag733
https://bio.site/invitoono692
https://bio.site/randusttales431
https://bio.site/chiasporabhar3
https://bio.site/caukocorless981
https://bio.site/minslogojob54

Write Comment
Return to News
  Displaying 201 through 201 of 201
Prev | First
  The time now is 7:33:52 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *