Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


July 25, 2008

Large ISPs Still Vulnerable to DNS Attack

RSS
Subscribe to Windows IT Pro | See More Domain Name System (DNS) Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

According to Neal Krawetz of Hacker Factor, several large ISPs still haven't patched their DNS servers to guard against a critical vulnerability that was made public two weeks ago.

Dan Kaminsky reported the flaw and took special care to ensure that information about the problem was kept quiet until major software vendors could make patches available. Exploits are already on the loose but meanwhile countless Internet users are at risk because their ISPs still haven't installed the available patches or taken steps to secure all their DNS servers through other methods.

According Krawetz's survey of 60 DNS servers, as of July 24 seventeen DNS servers are still vulnerable to attack. The offending ISPs including Comcast, Adelphia, BTInternet, Sprintlink, Bellsouth, Tmnet Streamyx, Xtra, and Wave Broadband.

Kaminsky also offered statistics that he gathered through a DNS vulnerability testing tool available on his website. Anyone can use the tool to test the DNS server currently configured in their TCP/IP settings. As of July 25, Kaminsky reports that the last 5,000 vulnerability tests conducted by the tool reveal that 2,503 are still vulnerable. Many of those vulnerable servers undoubtedly belong to major ISPs.

End of Article



Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Microsoft, News Corp. Discuss Locking Out Google

Microsoft and Rupert Murdoch's News Corp. recently discussed an alliance that would counter Google's fledgling online news service. ...

2009 Windows IT Pro Editors' Best and Community Choice Awards

Picking a favorite product from an impressive crowd of competitive offerings is never an easy task, and such was the case with our Editors' Best and Community Choice awards this year. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events Introduction to Identity Lifecycle Manager "2"

SQL Server Security: How to Secure, Monitor & Audit Your Databases

Protecting Mobile Users' Data

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement