Apple's fix for major DNS security hole finally arrives

By Ed Oswald | Published August 1, 2008, 3:40 PM

Nearly three weeks after Microsoft patched its Windows operating system to protect against attacks exploiting a flaw within the DNS system, Apple has delivered its own fix.

The DNS flaw, discovered by security researcher Dan Kaminsky, allows attackers to divert traffic to Web sites of their choice through an issue with BIND, software that powers DNS servers.

While a random transaction ID is produced to initiate the communication, certain setups cause the number of possibilities to decrease, thus making guessing the correct ID easier. Kaminsky even said there was a way to guess correctly in only a couple tries.

Microsoft's response was near immediate, as was Linux distributor Debian's. For unknown reasons, however, Apple did not fix the problem at the time of disclosure, and the exploit code's accidental leak late last month made action all the more necessary.

While Kaminsky was scheduled to detail the issue at the annual Black Hat conference on July 24, the exploit code appeared on the Internet a day earlier.

Microsoft saw the issue as so important that it took the unusual step of reminding customers of the patch on July 25. The company also acknowledged the existence of exploit code at that time.

For Apple customers, the DNS fix is available for Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.4, and Mac OS X Server v10.5.4. Users can download the security update through Apple's Web site or use the Software Update feature within the operating system.

In addition to the DNS patch, Apple also fixed a Microsoft Office file issue where a problem with QuickLook could lead to code execution, according to an advisory.

Comments

View comments by with a score of at least

How many people run a DNS server on their home computer?

Ok, that is who is affected by this bug.

How many public DNS servers run on OSX Server?

Ok, that is how many systems are affected by this bug.

So, 99.99999% of Mac, GNU/Linux and Vista/XP users are at zero risk of this affecting their home machines.

Who did have issues with this? People like your ISP or other entities which run DNS servers.

Gotta love the sensationalism of the story though. They even got a pot shot at Microsoft in the last paragraph. Anything to bring people to the site though.

Score: 0

|

Perhaps you might want to check your facts first next time before posting.

The vulnerability affects DNS clients too.

Score: 0

|

"The real vulnerability is not in Windows or Linux but in BIND, the most widely deployed DNS software everywhere. A security feature in BIND creates a transaction ID for communications between an IP host and a DNS server. Supposedly, that transaction ID is supposed to be randomized using a 15-bit binary number. But the way it's typically deployed, each limitation or option added to the system reduces the number of bits in that random number by one each time, and reduces the number of guesses a malicious script requires to guess the transaction ID by a power of two.

With that accomplished, a malicious user may be able to effectively "poison" the cache of DNS routers with table entries based on appropriately matching transaction IDs, but which point to improper IP addresses."

how does that affect a client? a client is simply using a DNS Server. If said server has been poisoned, the client has nothing to do with it.

Perhaps you might want to get a clue before posting.

Score: 0

|

Score: 0

|

This will be my last response to your trolling.

Your own link tells you it is a DNS Server issue you only will see if you run a DNS Server on your machine which 99.9999999% of people do not.

If the DNS server you are using is poisoned, there is nothing you can do no matter what OS you are using.

You fail again.

Score: 0

|

Well, I simply meant to highlight that the vulnerability does affect both DNS servers and DNS clients. Apple only patched the server portion.

Perhaps the explanation from this link is clearer: http://isc.sans.org/diary.html?storyid=4810

...shows it is -as a DNS client- still using incrementing ports.

and

So Apple might have fixed some of the more important parts for servers, but is far from done yet as all the clients linked against a DNS client library still need to get the workaround for the protocol weakness.

Score: 0

|

*Breaking News*

Apple admits OSX simply a skinned version of Microsoft Vista Home. MSFT added the main reason for Vista DRM is to lock down and limit features available to Apple users as a differentiator from the premium universal Vista product.

In a shared press release the two companies revealed secret collaboration had been going on for years after Apple realized their fashion designers had neither the talent nor skills to support a user base greater than 12.

To clear up confusion and streamline products it was announced that OSX will be marketed as Vista Lite'n'Pretty from 10.6 onwards.

Across the nation Apple users expressed their delight at these unexpected news. Groups were reportedly seen dancing around bonfires or gathering in large flocks and sipping Latte at Starbucks, the primary mating grounds for Mac users.

Score: 0

|

...or not.

"Apple's patch fails to fix DNS flaw" @ http://www.computerworld...c&articleId=9111363

Score: 0

|

Starting to get ridiculous. I guess the days of Apple as a reasonably secure platform are officially gone.

http://www.computerworld...c&articleId=9111398

Score: 0

|

Lol it never was secure. Just more under the radar.

Score: 0

|

But I thought "it just works" and only Windows/IE have "major" security holes. Oh dear, the lame TV ad propaganda has unraveled.

Score: 0

|

nah man it's just that apple fans have been brainwashed since the beginning ;)

Score: 0

|

If you are on a Mac you were secure from day one! Pure propaganda at it's best. Mac's are incapable of security vulnerabilities.

Score: 0

|

keep dreaming child, keep dreaming, why dont you just get out of your basement and drag your fat a** to the football try-outs at your school or college, oh yeah and thanks for calling me "f**got" but hey if you're calling me a f**got you must be one because you're assuming things that you don't even know

Score: 0

|

Is that also the reason why they are incapable of fixing even a simple security vulnerability such as this?

They didn't even have to do much research to fix the flaw because the way to fix it is very well-known.

Score: 0

|

Come on guys. U can't possibly take that guy serious!?!

Back on subject: "Researchers from security firm nCircle and the SANS Institute both report that fully patched versions of Tiger (10.4.11) and Leopard (10.5.4) remain vulnerable even after running a bevy of patches Apple released Thursday. Other vendors, including Microsoft, Sun Micro, released similar patches weeks ago."

Score: 0

|

"Come on guys. U can't possibly take that guy serious!?!"

Lol I stopped taking this guy serious a LOOOONG time again.

Score: 0

|

i guess

Score: 0

|

Mac OS has been the most insecure operating system for years. Nobody was interested in hacking Mac OS because until Apple switched to Intel x86 processors hardly anyone used Macintosh computers.

Score: 0

|

What's that you say? Apple have a flaw anywhere? No!

Score: 1

|

Google Buzz: Another attempt to harness the content firehose

Similar to how Google successfully remolded RSS into a Google tool, the company now wants to remold Gmail into one big Google party

Success: Google's Nexus One shipping support line takes tech support questions

UPDATED Though the support line had been set up for shipping, it now appears Google personnel are happy to hear technical concerns.

Goodnight, moon: What I learned from a space shuttle

Carmi Levy | Wide Angle Zoom: Can the tech sector learn a few lessons from the space program? Certainly, if you believe in learning from someone else's mistakes.

Netflix to FCC: NBCU + Comcast could bypass net neutrality

Weaning itself from the post office as its main means of video transfer, Netflix would like someone to ensure the Internet remains just as unencumbered.

Rhapsody to become an independent company

RealNetworks and Viacom subsidiary MTV Networks have begun the process of spinning off music service Rhapsody into an independent company.

Nvidia debuts new dynamically-switched graphics card technology

Today, Nvidia announced that its Optimus technology for GPU switching will soon be available in a handful of Asus notebooks.

Google lowers 'unusually high' early termination fee on Nexus One

Google has lowered the Nexus One's early termination fees which were twice as high as the norm.

Netgear and Ericsson introduce a mobile broadband hotspot with a twist

It's a mobile broadband hotspot, but it's for use in the home.

Report: Streaming video drove 72% global increase in mobile data consumption

A new study says streaming video is "the single most influential factor driving the need for increased mobile network capacity."

Stymied by continuing Nexus One 3G issues, Google blames the environment

If you're still afflicted with the 3G flip-flop trouble, then you might consider moving. That appears to be the only suggestion Google can give for now.

Wolfram|Alpha makes a strong argument for virtual keyboards

"Answer engine" Wolfram|Alpha has updated its iPhone/iPod Touch app, harnessing the strength of the virtual keyboard.