Security

DNS vulnerability gets massive patch – FUD spreading as masses panic

by Steve Ragan - Jul 9 2008, 19:20

Share


Share

Interested in a more interactive TTH? Join our Facebook Group
Want regular updates from The Tech Herald? Follow us on Twitter

Comment on this Story

Note our older Talkback system is still running below. We hope to import existing comments into the new system shortly. Guest posting is still allowed, however, you can now login with any number of social network accounts.

Talkback

Add your comment (no registration required)

page: 1 

Buck WheatJul 9th, 2008 - 22:14:57

Great patch! Ask anyone running ZoneAlarm. While removing the so-called 'fix', repeat today's mantra: 'Gates loves me. Ballmer loves me. I am a whole person.'

Report this comment

donppusaJul 9th, 2008 - 22:23:05

Yep....it wiped me out too. had to remove it to get back on the internet.

Report this comment

SteveJul 9th, 2008 - 22:38:08

I would not recommend that businesses underestimate this vulnerability. See tinyurl.com/57g8xu

Report this comment

Steve R - TTHJul 10th, 2008 - 00:01:31

@Steve
No, no one should discount any security issue, even low priority ones are serious. However, my point is that the press and mainstream blog owners blew this way out of proportion. So you are correct with your blog post and points here in the comments.

Transaction IDs have been predictable for years, why is it that this is such a huge deal now? I mean give me a break, “Internet flaw could let hackers take over the web” is the winner for the FUD driven headline of the month.

I also, while not mentioning it in the article, take offense to the press assuming that most IT workers would fail to realize that DNS issues can lead to problems, and were too stupid not to notice if a vendor released a patch.

The real story is that this was one of the few times, rare even, that vendors from all platforms released patches that deal with exactly the same issue. Nothing more or less.

My advice and opinion stands. If your vendor releases a patch, no matter what it is for, if it is even remotely security related apply it.

Report this comment

JamesJul 27th, 2008 - 10:32:21

There is a reson this flaw is being taken more seriously than last year's: It's more dangerous. (Also, Kaminsky announced it in a way guaranteed to draw maximum attention to it) I'd say 11 seconds to poison a DNS cache with this exploit (according to Paul Vixie in an email to NANOG) as opposed to the days it would've taken previously is worth sitting up and taking notice of.

Report this comment

page: 1 

Add your comment (no registration required)

AddThis Social Bookmark Button

Advertising

Advertising

Advertising

Latest

Review: Motorola Droid
Facebook settlement means little in the long run
Naked Windows 7 vulnerable to Malware if left in default state
Adobe patches Shockwave Player
SSL flaw allows man-in-the-middle attacks

Latest Articles on Monsters&Critics

Cyprus inaugurates new airport in Larnaca
Real beat luckless Atletico, stay one point behind Barca (Roundup)
'CSI: Miami' star Eddie Cibrian goes after tabloid
John Cusack reflects on his career
'Ghost Lab' uncovers the spectre of John Wilkes Booth, Nov. 10
Taiwan man has been catching rats for mom for 24 years
Camoranesi's brace triggers Juve's hammering of Atalanta (Roundup)
Pedro the hero as Barcelona thrash Mallorca (1st Lead)
Peres: "Peace process is not a lost case"
Djokovic, Federer to face off for fifth time this season (2nd Roundup)

Notice: Undefined index: continent in /home/thetechh/public_html/class/class.slot.php on line 173

Notice: Undefined index: continent in /home/thetechh/public_html/class/class.slot.php on line 173

Notice: Undefined index: continent in /home/thetechh/public_html/class/class.slot.php on line 173

Notice: Undefined index: continent in /home/thetechh/public_html/class/class.slot.php on line 173