Microsoft Patches Major DNS Bug, The Fix Interferes With Firewalls
By Alice Turner
20:55, July 9th 2008
26 votes
Vote this story
Microsoft Patches Major DNS Bug, The Fix Interferes With Firewalls

Microsoft released four patches Tuesday, one of which addresses a major DNS spoofing flaw exploited by malware. It's unclear why it was labeled "important" and not "critical", even though the two privately reported vulnerabilities in the Windows Domain Name System (DNS) enabled a remote attacker to redirect network traffic intended for systems on the Internet to another address, usually the attacker’s own systems.

Microsoft found a way around the flaw by using strongly random DNS transaction IDs, using random sockets for UDP queries, and updating the logic used to manage the DNS cache, the company's security bulletin MS08-037 reads. However, Microsoft is not the only company affected by the DNS flaw. Most of networking companies need to also solve this bug, including Cisco, the Internet Software Consortium, Juniper Networks, Microsoft, Nominum, Red Hat and Sun. Other companies which might need to address the issue are Akamai, Apple, Debian/GNU Linux, Fedora, FreeBSD, Gentoo, HP, IBM, Motorola, Nokia and Ubuntu.

However, Microsoft's fix interferes with software firewalls for Windows, because they are not coded to support the newly implemented security measures, which include the randomization of several source ports. The DNS flaw was apparently discovered by Dan Kaminsky of the Seattle-based security firm IOActive Inc.

The issue points out that the current Domain Name System (DNS) is outdated, and switching to the newer Domain Name System Security Extensions (DNSSEC) is imperative. While DNS provides various information associated with domain names, primarily returning the IP address of a certain hostname, DNSSEC does this in a different way, because answers in DNSSEC are digitally signed.

Deploying DNSSEC at the root level of the Internet Domain System will prevent many spam and spoof attacks and force Internet crooks to find other means of attacking users.

Patch Tuesday also saw another three vulnerabilities fixed. The most prominent of the remaining three patches is the one affecting Windows Vista and Windows Vista Service Pack 1, as well as Windows Server 2008. The code injection flaw it fixes enables remote code execution through a code injection flaw. This is the common way of attack for malware. The flaw was not tagged as critical, apparently because it doesn't work without the user first taking some extra actions or adding special software or drivers.

Of the remaining two, one targets the Microsoft SQL Server and one Microsoft Exchange Server.



© 2007 - 2008 - eFluxMedia
Tags: DNS, DNSSEC, patch
Share the News:
Del.icio.us Digg Stumble Upon Facebook Newsvine Mixx
dotclear

Other News in

Report: Confidential data again goes missing in Britain

London - A computer disk containing the personal data of around 5,000 prison workers in Britain has gone missing, in another case of several similar incidents that have embarrassed the British...

Google Wants To Take Over The World With Chrome Browser

Google Wants To Take Over The World With Chrome Browser

Google has launched its Google Chrome browser, and competitors are quite worried. They are worried not because Google has entered the browser war (which was expected for some time) but because Chrome...

The Dawn Of The Chrome Age

The Dawn Of The Chrome Age

One week ago, Google launched its open-source browser called Chrome, which is beta software aimed at catering for the consumers’ need to have a modern platform for their browsing and web...

The Gates And Seinfeld Ad

The Gates And Seinfeld Ad

The first Bill Gates - Jerry Seinfeld ad has arrived. It marks the largest consumer marketing campaign in the history of Microsoft, with a $300 million contract. Apparently the ad leads...

Ready To Rock? Two Days Left To Apple's San Francisco Event!

Ready To Rock? Two Days Left To Apple's San Francisco Event!

Although we have official confirmation of the September 9 event in San Francisco, we still know too little about what Apple is really going to do. So as we wait, rumors seem to multiply on a daily...

dotclear
Latest videos in Technology
Jerry Seinfeld Microsoft...
Sony recalls PCs
Citius, altius, electronicius
Inside The Bloggers Lounge
For Sharapova, Diamonds Are a...

dotclear
Technology You are here: Technology
» Technology   » Gadgets   » Video Games   
E-mail To A Friend Print RSS Text size: Decrease font size Increase font size
dotclear
dotclear
dotclear
Most Popular in Technology
Large Hadron Collider Raises Much ConcernLarge Hadron Collider Raises Much Concern

» read full story
dotclear

Interested In This Topic?

News Alert will keep you informed. Find out more.
dotclear
Photos Gallery
dotclear
Today's Latest News
On Your Marks! Get Set!  VMAs!On Your Marks! Get Set! VMAs!

» read full story
dotclear