Scary Internet Security Story of the Day

Charles Johnsonfollow me on twitter
Thu Aug 7, 2008 at 1:22 pm PDT • Views: 216

The serious bug discovered recently in most of the world’s DNS servers has even greater implications, according to security expert Dan Kaminsky: Major Internet security flaw also affects e-mail.

LAS VEGAS - A newly discovered flaw in the Internet’s core infrastructure not only permits hackers to force people to visit Web sites they didn’t want to, it also allows them to intercept e-mail messages, the researcher who discovered the bug said Wednesday. …

Dan Kaminsky of Seattle-based security consultant IOActive Inc. exposed a giant vulnerability in the Internet’s design that, in one case, allowed hackers to reroute some computer users in Texas to a fake Google.com site loaded with automated advertisement-clicking programs, a scam to generate profits for the hackers from those clicks. The flaw wasn’t in the site itself, it was in the back-end machines responsible for guiding computers to that site.

The vulnerability Kaminsky found is especially insidious because it allows criminals to tamper with machines whose reliability and trustworthiness is critical for the Internet to function properly. …

While some details leaked out early — security researchers accurately guessed parts of Kaminsky’s discovery — he was able to keep a few juicy bits secret until the talk.

One of those was the susceptibility of many e-mail servers to the DNS vulnerability, an opening that gives criminals a way to plant themselves in the middle of the transmission from the sender to the recipient and redirect messages to their own servers, Kaminsky said. The result: criminals have a way not only to comb through the contents of those messages, but also to gain access to other password-protected Web sites the victims belong to.

That’s because most sites have a feature that allows members to retrieve their passwords by e-mail if they’ve forgotten them. If a criminal has access to the account where that message is sent, he can then begin snooping on the contents of that account, from e-mail, to banking, to retailer sites.

Advertisement

136 comments

^ back to top ^

Name:

Pass:

Register Forgot Your Password? Account Settings Re-send Confirmation (To log in, cookies must be enabled in your browser!)

Turn off ads by subscribing!
For about 33 cents a day, our subscription option turns off all advertisements at LGF!
Read more...


► LGF Headlines

  • Loading...

► Tweeted Articles

  • Loading...

► Tweeted Pages

  • Loading...

► Top 10 Comments

  • Loading...

► Bottom Comments

  • Loading...

► Recent Comments

  • Loading...

► Tools/Info

► LGF Hits

► Resources

► Never Forget

► Statistics

► Tag Cloud

► Contact

You must have Javascript enabled to use the contact form.
Your email:

Subject:

Message:


Messages may be published in our weblog, unless you request otherwise.
Tech Note:
Using the Contact Form

More Partners

Compare Electricity Prices in your area. Texas Electricity is deregulated; you have the right to choose Texas Electric Rates from among many Texas Electric Companies.

What's the ugliest part of your body?

TwitterFacebook
LGF Pages
Recent Pages

Channeling Confucius
Athens Burns as Parliament Prepares to Vote on Greek Bailout - the Atlantic Wire
3 hours, 47 minutes ago
Views: 94 • Comments: 0
Tweets: 0 • Rating: 1

researchok
Soros Undecided on Pro-Obama Super PAC Political Ticker Blogs
5 hours, 15 minutes ago
Views: 135 • Comments: 1
Tweets: 0 • Rating: 2

researchok
Central Athens Burns as Lawmakers Weigh Austerity
5 hours, 16 minutes ago
Views: 113 • Comments: 0
Tweets: 0 • Rating: 1

researchok
Help in European Financial Crisis Could Spawn 'Zombie Banks'
5 hours, 17 minutes ago
Views: 108 • Comments: 0
Tweets: 0 • Rating: 1

researchok
Writer Extradited Over Tweets on Prophet Mohammed
5 hours, 17 minutes ago
Views: 136 • Comments: 1
Tweets: 1 • Rating: 1

Channeling Confucius
CPAC 2012: Are the Republican Party's Views on Gay Marriage Shifting?
7 hours, 40 minutes ago
Views: 154 • Comments: 1
Tweets: 0 • Rating: 1

Curt
U.S. Federal Deficits, Presidents, and Congress (Updated 09/2011)
10 hours, 22 minutes ago
Views: 148 • Comments: 1
Tweets: 0 • Rating: 4

Look At My New Grandbaby!
EPIC FAIL: Religious Magazine Mistakenly Publishes Smutty Content
11 hours, 1 minute ago
Views: 260 • Comments: 2
Tweets: 3 • Rating: 3

Randall Gross
Lasers Plus a Crushing Magnetic Field May Make Fusion More Efficient
11 hours, 22 minutes ago
Views: 191 • Comments: 0
Tweets: 0 • Rating: 4

Randall Gross
White House: Matter of Time Before Assad Falls
11 hours, 24 minutes ago
Views: 149 • Comments: 0
Tweets: 0 • Rating: 2

 Frank says:

I'm not black, but there's a whole lot of times I wish I could say I'm not white.