China Netcom falls prey to DNS cache poisoning

RichardG

Honorary Master
Joined
Apr 6, 2005
Messages
11,700
Reaction score
34
Location
Johannesburg/Jozzi South Africa
Source:
http://www.networkworld.com/news/2008/082108-china-netcom-falls-prey-to.html?hpg1=bn

One of China's largest ISPs (Internet service providers) has fallen victim to a dangerous vulnerability in the Internet's addressing system, according to security vendor Websense.

The flaw, which has been described as one of the most serious ones to ever affect the Internet, can cause Web surfers to be redirected to fraudulent Web sites even if the URL (Uniform Resource Locator) has been typed correctly in a browser's address bar.

Discovered by security researcher Dan Kaminsky, the problem is rooted in the DNS (Domain Name System). When a user types a Web address into a browser, the request goes to a DNS server or a cache, which returns the corresponding numerical IP (Internet protocol) address for a Web site.

But the flaw allows the DNS server to be filled with wrong information and direct users to malicious Web sites. The China Netcom attack is particularly interesting because it only affects those who misspell certain URLs, said Carl Leonard, security research manager for Websense's European lab.
 
Top
Sign up to the MyBroadband newsletter
X