Wired: Kaminsky DNS Write Up
Wired Magazine has published an outstanding piece (and today’s MustRead) focusing on Dan Kaminsky’s (IOActive Director, Penetration Testing Services) discovery, announcement and subsequent mitigation of the now well-known DNS Cache Poisoning Exploit. Included in the story are some of the main actors (Vixie, Gustafsson, etc.) in the underpinnings of the interwebs… Read a short snippet of the Wired story, (I have also included a short YouTube video featuring Dan – from BlackHat Briefings) and get those DNS servers patched….geez.
From the Wired post: “In June 2005, a balding, slightly overweight, perpetually T-shirt-clad 26-year-old computer consultant named Dan Kaminsky decided to get in shape. He began by scanning the Internet for workout tips and read that five minutes of sprinting was the equivalent of a half-hour jog. This seemed like a great shortcut—an elegant exercise hack—so he bought some running shoes at the nearest Niketown. That same afternoon, he laced up his new kicks and burst out the front door of his Seattle apartment building for his first five-minute workout. He took a few strides, slipped on a concrete ramp and crashed to the sidewalk, shattering his left elbow.
He spent the next few weeks stuck at home in a Percocet-tinged haze. Before the injury, he’d spent his days testing the inner workings of software programs. Tech companies hired him to root out security holes before hackers could find them. Kaminsky did it well. He had a knack for breaking things—bones and software alike…”
- DefCon 16 Provides Early Release Video & Tools
- Kaminsky Video Posted
- BlackHat: Kaminsky’s Grandmother Bakes Session Cookies
- Kaminsky BlackHat Presentation Slides Posted
- Apple DNS Patch Problem: No Fix For MAC Clients!
- Apple Security Patches Address DNS Flaws, Several Other Vulnerabilities
- DNS Entropy Testers – Is Your DNS Infrastructure Vulnerable?
- Microsoft Releases Security Advisory 956187: DNS Spoofing Threat
- Kaminsky Reveals Exploit During BlackHat Webinar
- Metasploit Releases DNS Exploit Code
- Kaminsky’s DNS Flaw Exposed Early, Attackers Working Furiously
- DNS Vulnerability Originally Discovered By SANS GSEC Student
- US-CERT: Multiple DNS Implementations Vulnerable to Cache Poisoning
- Securosis: Large Scale DNS Vulnerabilty

![Reblog this post [with Zemanta]](http://img.zemanta.com/reblog_b.png?x-id=5504214c-3e3f-4cbb-95f8-b2581a1d5a3b)






May 6th, 2010 at 21:35
@ChrisPirillo check this out: http://bit.ly/9Fde5D http://bit.ly/aVmqbr. old yet interesting. I want to call in to ask you about it. Cheers