Software flaws put internet at risk

Four separate vulnerabilities have been discovered in the software used by most of the internet's domain name system servers, putting parts of the network at risk.

Written by John Geralds in Silicon Valley

Four separate vulnerabilities have been discovered in the software used by most of the internet's domain name system (DNS) servers, putting parts of the network at risk.

The flaws discovered in two widely used versions of BIND (Berkeley Internet Name Domain), an implementation of DNS, could allow a malicious user to gain super-user privileges and execute code that would disrupt servers running the software.

DNS servers translate domain names into numerical IP addresses - for example, 11.11.11.11 - which are used to identify servers. The system lets web surfers use memorable domain names, rather then strings of numbers, to locate websites.

Jim Magdych, research manager at Network Associates business unit, PGP Security, said: "If this vulnerability was exploited by an attacker, all internet traffic relying on a vulnerable server could be brought to a halt."

He added: "Depending on a corporation's network configuration, a hacker could take advantage of the vulnerability to compromise the server and launch further attacks, potentially allowing the attacker access to internal networks."

The vulnerability exists in versions 4 and 8 of BIND, though not in the recently released version 9. Three of the four flaws were identified by researchers at PGP Security.

Technical information on upgrading is available from the Coordination Centre at Carnegie Mellon University at http://www.cert.org/advisories. The ISC has also posted new versions of the software on its website at www.ISC.org.

Tags:

Further reading

DNS not bound by Bind

Vulnerabilities prompt rise in alternatives   More...

Top company websites are hackers' dream

250 multinational corporates could lose their .coms because of wacky DNS protection   More...

OpenPGP flaw confirmed

Czechoslovakian security group ICZ, which made a vague warning about vulnerabilities in PGP encryption software at the start of the week, has released a more detailed advisory of the flaw.   More...

OpenPGP set to become global standard

Godfather of encryption and creator of PGP, Phil Zimmermann, has moved over to security company Hush Communications, in a bid to set a global standard for encryption in digital communication and strike a killer blow for privacy on the web.   More...

Related articles

Domain Name System still at risk

Global DNS is 'as vulnerable as ever', reports Infoblox   More...

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Kaspersky falls through Online Scanner flaw

Security firm unaware of 'highly critical' vulnerability   More...

Carnegie Mellon floats anti-phishing game

Game on for Anti-Phishing Phil   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement