Today´s DiaryIf you have more information or corrections regarding our diary, click here to contact us.
Published: 2008-07-22,
0 comment(s)
Last Updated: 2008-07-24 05:03:35 UTC by Swa Frantzen (Version: 5) It seems the cat might be out of the bag regarding Dan Kaminsky's upcoming presentation at Blackhat. Since this now means the bad guys have access to it at will -I found the speculations using Google, I'm sure they have done so already-, the urgency of patching your recursive DNS servers just increased significantly. There seems to be some effort underway to put the cat back in the bag, but I strongly doubt that'll work. To describe it for defensive use by those operating recursive DNS servers: The descriptions I found would make you look for signs of attack using this technique in DNS queries for significant amounts of nonexistent subdomains that try to poision the parent using a glue record. Since I wasn't briefed by Dan Kaminsky, I've no way of knowing if the theories that are out there are in fact what was going to be presented at Black Hat, so it might still be different. Still, while fixing this might not be so trivial, an upgrade or patch of all recursive DNS servers is what's really needed at this point. So if you were still waiting for an excuse, this one is it: PATCH NOW. UPDATE:
UPDATE:
UPDATE:
Thanks to all who wrote this in. UPDATE:
See http://blog.wired.com/27bstroke6/2008/07/dns-exploit-in.html
--
Keywords: DNS
0 comment(s)
Published: 2008-07-22,
0 comment(s)
Last Updated: 2008-07-22 16:52:36 UTC by Mari Kirby Nichols (Version: 1) One of the researchers involved in the project has released the source code for the utilities. The utilities are used to lift crypto keys from memory even after a reboot. The source code was revealed at the 2600 Hackers on Planet Earth (HOPE) conference over the weekend. If you aren’t up-to-date on this interesting subject, here are the links to previous diary entries by Swa Frantzen back in February.
You can see the research paper, a video explanation and the utility source code here: http://citp.princeton.edu/memory/
Don’t forget that Ed Skoudis and Tom Liston are speaking on this very subject in relation to how this methodology can be applied to Pen Testing and forensics at SANSFIRE in DC this Friday night, July 25th. Their SANS@Night session starts at 7pm. http://www.sans.org/sansfire08/night.php
Keywords: cold boot utility code
0 comment(s)
If you have more information or corrections regarding our diary, click here to contact us. Diary Archive
Search Diaries: |
Featured EventPollTrends
more details
World Map
|