Forum Home
Press F1
 
Thread ID: 91975 2008-07-24 10:59:00 DNS attack code publicised Robin S_ (86) Press F1
Post ID Timestamp Content User
691688 2008-07-24 10:59:00 I presume there is some factual basis for this story. What a great "security" company to release a bomb like that!

news.yahoo.com
Robin S_ (86)
691689 2008-07-24 11:18:00 I read something on this last week sometime. Apparently they only released the code AFTER the flaw had been patched Myth (110)
691690 2008-07-25 00:13:00 They have known of this problem for six months or more now....

That's what that ms update (the one made problems for Zone Alarm) was for a week or 2 back

As Myth says, they only released the info after the fix was coded
bevy121 (117)
691691 2008-07-25 00:45:00 I presume there is some factual basis for this story. What a great "security" company to release a bomb like that!

news.yahoo.com

It drives development and action to fix it. If it weren't publicised, some people wouldn't patch themselves so the attackers who -are- aware of it can take advantage of them.
utopian201 (6245)
691692 2008-07-25 03:18:00 so Dan Kaminisky found this issues early this year.
he has spent many months working with big verders on a patch.

on July 8th all the big verders released a patch, and Dan told the world that he would make all the details public on Aug 7th.

all of us network people started patching......

many of us doing the patching noticed that the new code for DNS made the source port for request be a random port, thats interesting....

on the 21st, the full description of the vulnerability was leaked.

a high tech view of the bug for the super geek
blog.invisibledenizen.org

a softer version for the less geek
beezari.livejournal.com

on the bright side, if you use openDNS you will be fine as they have patched.

on the down side, only about half on New Zealnds ISPs have patched....
robsonde (120)
691693 2008-07-26 12:11:00 bump.
I feel that keeping this in the minds of user is good......

one of the big three IPS still have not patched.......
robsonde (120)
1