Log in to your IBTimes Account

close
ID
Password

Giant online security hole getting fixed, slowly



By JORDAN ROBERTSON, AP
05 August 2008 @ 05:36 pm EST

SAN FRANCISCO - A giant vulnerability in the Internet's design is allowing criminals to silently redirect traffic to Web sites under their control. The problem is being fixed, but its extent remains unknown and many people are still at risk.


Internet Security Hole
In this undated photo provided by IOActive Inc., Dan Kaminsky, director of penetration testing for Seattle-based computer security consultant IOActive Inc., is shown. (AP Photo/IOActive Inc.)
1 of 1

Related Topic

Get stories by e-mail on this topic.

E-mail:
Quotes
VRSN 18.98 -0.67
ATT 23.95 -0.05
MSFT 19.11 -0.76
CSCO 15.33 -0.68
JAVA 3.22 0.03

SYMBOL LOOKUP

The gaping security hole enables a scam that targets ordinary people typing in a legitimate Web address. It happens because hackers are now able to manipulate the machines that help computers find Web sites. If the trick is done properly, computer users are unlikely to detect whether they've landed at a legitimate site or an evil double maintained by someone bent on fraud.

Security experts fear an open season for virus attacks and identity-fraud scams.

"It's kind of like saying, `There's a bunch of money on the street. If you can get over there soon enough, you can get it,'" said Ken Silva, chief technology officer for VeriSign Inc., which manages the ".com" and ".net" directories of Internet addresses. "It's something the industry is taking seriously. You'd be in a bad place if you weren't doing something about it."

The bug's existence was revealed nearly a month ago. Since then, criminals have pulled off at least one successful attack, directing some AT&T Inc. Internet customers in Texas to a fake Google site. The phony page was accompanied by three programs that automatically clicked on ads, with the profits for those clicks flowing back to the hackers.

There are likely worse scams happening that haven't been discovered or publicly disclosed by Internet service providers. "You can bet that the (Internet providers) are going to stay tightlipped about any attacks on their networks," said HD Moore, a security researcher.

The AT&T attack probably would have stayed quiet had it not affected the Internet service of Austin, Texas-based BreakingPoint Systems Inc., which makes machines for testing networking equipment and has Moore as its labs director. He disclosed the incident in hopes it would help uncover more breaches.

The underlying flaw is in the Domain Name System (DNS), a network of millions of servers that translate words typed into Web browsers into numerical codes that computers can understand.

Getting from one place to another on the Internet typically requires a trip through several DNS servers, including some that accept incoming data and store parts of it. That opens them up for potential attack.

Copyright 2008 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

    Click!
  • Rate this article:

Comments

Post Your Comment

You must be an IBTimes member to post a comment. Login | Register


advertisement
More Technology
If activist investor Carl Icahn is going to profit from his $1.8 billion bet on Yahoo Inc., the billionaire needs the struggling Internet company's stock...
Microsoft Corp. on Thursday tapped a former Yahoo search executive to lead its online push, adding to the intrigue surrounding a possible search partners...
Shares of Red Hat Inc. climbed Thursday after a Jefferies analyst upgraded the software distributor, noting its 100 percent recurring revenue stream, whi...

Advertisement
Build Business Credit for your company with NO PERSONAL GUARANTEES!

Building your business and corporate credit for your small business.

Bay area web design

Custom web design firm in bay area, Deographics

advertisement
 
IBTimes.com Web
Partners
International Business Times© 2008 The Ibtimes Company. All Rights Reserved. Terms of service | Privacy Policy | Advertising | About Us | Contact Us | Archives