DNS researcher claims 35 ways to exploit flaw
Dan Kaminsky has told the Black Hat conference that the DNS security flaw is even worse than expected.
 
The security researcher who uncovered the DNS security flaw has said it could be worse than previously thought, and offers attackers some 35 ways to exploit cache poisoning.
Speaking at the Black Hat hacker conference in Las Vegas, Dan Kaminsky highlighted how the flaw could be used to redirect users to malicious sites, as well as to intercept or edit email.
Kaminsky ran through another scenario in which a website could be tricked into sending a username and password to an email account controlled by a malicious attacker, using a forgotten password reminder.
These attacks are all made possible by the flaw, which allows attackers to poison DNS caches and redirect users to malicious third-party sites, even when they have correctly entered the address of a different, legitimate site.
Because the attack targets a fundamental service that powers the internet there are multiple ways it could be used for nefarious purposes; 35 at Kaminsky's count.
The security vulnerability was first discovered over six months ago, but Kaminsky revealed no details of it to allow an unprecedented collaboration between Microsoft, Sun and Cisco to develop a fix.
Despite only being recently announced, reports suggest that the flaw is already being used. AT&T has announced that it spotted an attempt to redirect users accessing www.google.com to a third-party website hosting advertisements.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Last month, Kaminsky said precautions taken to protect systems against the flaw were not strong enough, and Microsoft warned that attacks were "imminent".
- 
 AI layoffs could spark a new wave of offshoring AI layoffs could spark a new wave of offshoringNews Analysts expect a wave of rehiring next year in the wake of AI layoffs. That may sound like good news for workers, but it'll probably involve offshoring or outsourcing. 
- 
 Hackers are using these malicious npm packages to target developers Windows, macOS, and Linux systems Hackers are using these malicious npm packages to target developers Windows, macOS, and Linux systemsNews Security experts have issued a warning to developers after ten malicious npm packages were found to deliver infostealer malware across Windows, Linux, and macOS systems. 
- 
 DNS loophole could allow hackers to carry out “nation-state level spying” DNS loophole could allow hackers to carry out “nation-state level spying”News Sensitive data could be accessed from corporate networks using vulnerability 
- 
 What is DMARC and how can it improve your email security? What is DMARC and how can it improve your email security?In-depth Protect your customers and brand rep with this email authentication protocol for domain spoofing 
- 
 Cloudflare and Apple launch privacy-focused DNS protocol Cloudflare and Apple launch privacy-focused DNS protocolNews Oblivious DNS-over-HTTPS safeguards users' browsing habits from third parties 
- 
 What is DNS? What is DNS?In-depth We explain what DNS is, how it works, and how outages can be avoided 
- 
 D-Link routers under siege from months-long DNS hack D-Link routers under siege from months-long DNS hackNews The attackers are running malicious IPs through a Google Cloud Platform virtual machine 
- 
 SMBs warned over corrupted SOHO router risk SMBs warned over corrupted SOHO router riskNews Team Cymru researchers claim 300,000 routers may have had their DNS settings changed by cyber criminals. 
- 
 Will the FBI close down your online business this March? Will the FBI close down your online business this March?In-depth In tackling the DNSChanger botnet, the FBI may take a load of businesses offline. Davey Winder is, unsurprisingly, anxious... 
- 
 DNS Changer botnet smashed in major cyber crime bust DNS Changer botnet smashed in major cyber crime bustNews A botnet that is thought to have earned its controllers $14 million is dismantled.