Sponsored White Papers, Webcasts, and Downloads
ZDNet Resources
- Microsoft joins 'patch DNS now' chant; Apple patch missing
- On the heels of the release of weaponized exploit code for the DNS cache poisoning vulnerability, Microsoft has joined the chorus of security pros pleading with DNS server providers to immediately apply patches to protect users from malicious attacks. The Redmond, Wash. security...
- Tags: Apple Macintosh, DNS, Vulnerability, Apple Inc., Exploit Code, Microsoft Corp., Attack, Dan Kaminsky, Domain Names, Apple Mac OS X, Networking, Security, Internet, Operating Systems, Software, Apple Mac OS, Ryan Naraine
- Blog posts 2008-07-25
- How OpenDNS, PowerDNS and MaraDNS remained unaffected by the DNS cache poisoning vulnerability
- The short answer is being paranoid about tackling a known vulnerability. It's 2001, and Daniel J. Bernstein DJB, author of the then popular djbdns security-aware DNS implementation, is applying basic math principles to raise awareness on what's to turn into the "sky is falling" critical Internet vulnerability in 2008, in...
- Tags: DNS, Vulnerability, Anomaly, Attack, OpenDNS, MaraDNS, NSS, Domain Names, Networking, Internet, Dancho Danchev
- Blog posts 2008-07-25
- Kaminsky suggests long-term fix will still have to be determined, but patch now, or pay soon
- I listened to the Black Hat webcast today to grab as much info as I could on this subject. The biggest thing that I heard from the whole talk is that the patch fixes things to a reasonable point, but that long-term, there will have to be more work...
- Tags: CERT, DNS Server, Server, Kaminsky, Dan, Patches, Domain Names, Security, Internet, Nathan McFeters
- Blog posts 2008-07-24
- AT&T iPhones exposed to DNS cache poisioning? Or not?
- Here's a photo of my iPhone after running Dan Kaminsky's Doxpara DNS Checker tool a few minutes ago: I ran the same test at the DNS-OARC's DNS checker and got this: 209.183.33.23 (schinetdns.mycingular.net) appears to have GREAT source port randomness and GREAT transcation...
- Tags: DNS, AT&T Corp., Domain Names, Networking, Internet, Ryan Naraine
- Blog posts 2008-07-24
- News to know: DNS flaw; Amazon; Microsoft shakeup; Facebook
- Notable headlines: Ryan Naraine: Researchers borrow from Google PageRank for network defense service Attack code published for DNS flaw Nate McFeters: |)ruid and HD Moore release part 2 of DNS exploit 'Spam King' escapes from federal prison iPhone vulnerable to phishing,...
- Tags: Apple iPhone, Facebook, DNS, Amazon.com Inc., Microsoft Corp., Microsoft Xbox, Flaw, Game Players, Domain Names, Networking, Security, Consumer Electronics, Personal Technology, Internet, Larry Dignan
- Blog posts 2008-07-24
- Code Diffs for DNS Exploit Code
- Diffs between revisions of the exploit code released by HDM and |)ruid. Generated by Billy Rios. by Nathan McFeters
- Tags: Revision, DNS, Exploit Code, Domain Names, Networking, Internet, Nathan McFeters, diffs, code, Exploit, HDM, |)ruid, Billy, Rios, McFeters, Nate, Nathan, screenshots
- Image galleries 2008-07-23
- |)ruid and HD Moore release part 2 of DNS exploit
- [Updated 07/24/2008: Gallery images of diffs of code revisions has been included and will be updated as things change, see here.] Earlier today, noted researchers |)ruid and HD Moore released exploit code for the Metasploit tool for attacking the DNS flaw that was originally reported by Dan...
- Tags: DNS, Domain, Server, Entry, Exploit, NS, NS Record, Domain Names, Networking, Internet, Nathan McFeters
- Blog posts 2008-07-23
- News to know: Yahoo; VMware; Apple; DNS vulnerability
- Notable headlines: Ryan Naraine: Vulnerability disclosure gone awry: Understanding the DNS debacle RIM ships fix for BlackBerry code execution bug Dancho Danchev: Georgia President's web site under DDoS attack from Russian hackers 75% of online banking sites found vulnerable to security design...
- Tags: Apple iPhone, Google Inc., Larry Dignan, DNS, Yahoo! Inc., Vulnerability, Dana Blankenhorn, Health Care, Apple Inc., VMware Inc., App Store, Banking, Vertical Industries, Domain Names, Benefits, Healthcare, Security, Financial Services, Enterprise Software, Software, Internet, Human Resources
- Blog posts 2008-07-23
- Vulnerability disclosure gone awry: Understanding the DNS debacle
- On July 7, the day before the release of the patch for the now infamous DNS design flaw, hacker Dan Kaminsky with the help of Black Hat conference organizers invited reporters to a press conference to "discuss the massive multivendor patch being released this Tuesday." "A synchronized...
- Tags: Black Hat, DNS, Conference, Dan Kaminsky, Thomas Ptacek, Domain Names, Patches, Security, Networking, Internet, Ryan Naraine
- Blog posts 2008-07-22
- Has Halvar figured out super-secret DNS vulnerability?
- [ UPDATE: Kaminsky has all but confirmed that, yes, the cat is out of the bag ] It looks very much like the nitty gritty of Dan Kaminsky's super-secret -- and heavily hyped -- DNS cache poisoning vulnerability has been figured out by reverse engineering guru Halvar...
- Tags: DNS, Vulnerability, Server, Referral, Mallory, Domain Names, Networking, Security, Internet, Ryan Naraine
- Blog posts 2008-07-21
- Kaminsky to discuss DNS flaw at Black Hat sponsored webcast
- The Black Hat group on Twitter provided a message today alerting people to a webcast to be put on by Dan Kaminsky on the DNS vulnerabilities that I've heavily covered as follows: Dan Kaminsky breaks DNS, massive multi-vendor patch coming, details at Black Hat Vegas '08 ...
- Tags: Black Hat, Webcast, DNS, Flaw, Domain Names, Networking, Internet, Nathan McFeters
- Blog posts 2008-07-15
- News to know: iPhone; DNS patch; Online privacy; VMware; Vista
- Notable headlines: Tom Steinert-Threlkeld: A Modest Privacy Proposal Richard Koman: Congress looks at next-gen ad networks Techmeme: iPhone reviews Matthew Miller: MSM Apple iPhone reviews are up and may just have saved me some cash ...
- Tags: Apple iPhone, DNS, Online Privacy, Microsoft Windows Vista, Apple Inc., VMware Inc., Microsoft Corp., HP iPAQ 910, 3G, Domain Names, Cellular Phones, Wireless, Networking, Consumer Electronics, Personal Technology, Internet, Larry Dignan
- Blog posts 2008-07-09
- Don't doubt Deputy Dan
- Well, it would seem that Tom Ptacek may have figured out something to do with Dan Kaminsky's earlier DNS flaw, and this may actually be the vulnerability to fear that we had originally heard. Let's just say this, I've read Tom's postings on the Matasano blog for quite some time...
- Tags: DNS, Domain Names, Networking, Internet, Nathan McFeters
- Blog posts 2008-07-08
- Kaminsky and Ptacek comment on DNS flaw
- Well, well, well, what a day for security news! I got a chance to get the scoop word of mouth from Dan Kaminsky of IOActive (pictured above [image courtesy of quinnums]) and Thomas Ptacek of Matasano pictured below on the DNS flaw that's been all over the...
- Tags: DNS, Flaw, Nate, Domain Names, Networking, Security, Internet, Nathan McFeters
- Blog posts 2008-07-08
- Dan Kaminsky breaks DNS, massive multi-vendor patch coming, details at Black Hat Vegas '08
- It would seem there's a bigger story to that MS08-037 flaw that came out for Patch Tuesday today. From Dave Lewis over at the Liquid Matrix security blog: Today Dan Kaminsky released a first, as far as I can recall. A coordinated patch was released today...
- Tags: Black Hat, DNS, CERT, Flaw, Mogull, Updates, Domain Names, Networking, Security, Internet, Nathan McFeters
- Blog posts 2008-07-08
- Domain Fetcher (msi)
- Since 2003, Domain Fetcher has helped domain resellers and entrepreneurs to make the most of their efforts in searching for expired and unregistered domain names. No more monthly fees for similar browser based services. No more wasted hours typing in name after name hoping to find good ones to register....
- Tags: Domain Fetcher, Entrepreneurship, Domain Names, Web Browsers, Management, Internet
- Software downloads 2008-07-08
- Could some uses of OpenID create a large privacy issue?
- I just finished a news story about VeriSign's (NASDAQ: VRSN) secure OpenID services chosen by Microsoft for HealthVault users. The story discusses VeriSign's DNS services and its OpenID services and asks if this is a problem or a feature. Is this a possible privacy issue or could the two technologies...
- Tags: DNS, VeriSign Inc., Privacy, Domain Name, OpenID, Domain Names, Security, Networking, Internet, Tom Foremski
- Blog posts 2008-06-30
- '.wow': ICANN to allow almost any domain suffix
- The Internet Corporation for Assigned Names and Numbers has accepted a proposal allowing companies, cities and others to use almost any suffix they want for a web address. At its meeting in Paris, the Internet Corporation for Assigned Names and Numbers ICANN, a not-for-profit organization that...
- Tags: Web, ICANN, Domain, Suffix, Web Site, Web Site Development, Web Technology, Channel Management, Internet, Marketing, Marguerite Reardon, domain names, cybersquatter
- News items 2008-06-27
- ICANN and IANA's domains hijacked by Turkish hacking group
- What happens when the official domain names of the organizations that issue the domain names in general, and provide all the practical guidance on how the prevent DNS hijacking, end up having their own domain names hijacked? A wake up call for the Internet community. The official...
- Tags: Hacking, DNS, ICANN, Domain, Domain Name, Internet Assigned Numbers Authority, Domain Names, Internet, Networking, Dancho Danchev
- Blog posts 2008-06-26
- EZDNSWatch From CYBERsitter (exe)
- EZDNSWatch will check and monitor your computers DNS settings to prevent them from being hijacked. EZDNSWatch also supports OpenDNS and allows one click configuration. OpenDNS is a free public DNS server that is guaranteed safe and also provides protection from phishing and other dangerous sites you might accidentally encounter while...
- Tags: Solid Oak Software, OpenDNS, Phishing, Domain Names, Internet, Cyberthreats, Spam, Security, Spam And Phishing
- Software downloads 2008-06-24
White Papers and Webcasts