Security lab warns of possible Chinese ISP DNS exploit

By Scott M. Fulton, III | Published August 22, 2008, 6:20 PM

An apparent case of DNS poisoning in the caches of a major China-based ISP is causing extra concern today, in light of security engineer Dan Kaminsky's recent warnings about just how serious a cache poisoning exploit could become.

Visual evidence posted by security company WebSense earlier this week shows DNS resolution calls placed to the IP address of Chinese ISP Netcom using the command line tool nslookup, redirected to a completely different source whose IP address is linked to China. There, WebSense says, instead of the user's regular home page or Web mail, he'll see instead some links to exploits for RealPlayer, Adobe Flash Player, and Microsoft Snapshot Viewer.

Although it publishes its own financial status like a public corporation, China Netcom is one of four pillars of that country's state-run telecommunications system, which collectively reaps the equivalent of $160.2 billion in revenue per year, according to a report by China's Xinhua press released just today. In an annual report last March, China Netcom reported serving 19.768 million broadband subscribers, at an annual growth rate of 37%; and 110.82 million dial-up subscribers, declining by 2.8% annually.

DNS cache poisoning is certainly not a new concept. In fact, it could very well date back to the Master's thesis of then-Purdue student Christoph Schuba in 1993. "Because the Domain Name System is distributed among many thousands of hosts, it can be a critical mistake to blindly trust the resolved binding," Schuba wrote 15 years ago. "This thesis shows that under some assumptions it is no major effort to falsify the host name and authorization for a system."

Despite that fact, many press sources today came to the conclusion that the Netcom incident was caused by the specific exploit discovered by Doxpara security researcher Dan Kaminsky, whose details, he admitted, were revealed by way of public speculation late last month. WebSense's research has only uncovered evidence that a DNS exploit had occurred through cache poisoning, though it is probably impossible to discern through that evidence alone whether the method used was Kaminsky's.

A check of the accuracy of routing to Netcom's IP address via its DNS address by BetaNews this afternoon, revealed no address thwarting was taking place.

Comments

View comments by with a score of at least

um.. what does having a mac have to do with it?

Score: 0

|

A Mac and http://www.opendns.com is all you need to take care of this problem.

Score: 0

|

A Mac? Apple is the only major OS vendor that has NOT properly patched the DNS exploit. Apple released their patch on 7/31 and reports began surfacing as early as the next day that Apple's patch doesn't work. To date, nothing has changed. So tell me why is the Mac immune?

http://www.theregister.c...01/osx_still_vulnerable/

Test your DNS vulnerability here:

http://www.snipurl.com/dnstest

Score: 0

|

Score: 0

|

The Kool-Aid is poisoned.

Score: 0

|

Russia and China are where all of our (my day job) attacks come from. They just keep comin'.
Those 2 countries need to have stronger controls on internet security. It's as if the hackers are not in any risk.

http://afewtips.com

Score: 0

|

Microsoft's Ray Ozzie: 'Nobody's going to be 100% open'

The mobile apps ecosystems of the world may converge over time, led by apps being ported over across platforms, according to the Chief Software Architect.

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

The fallacy of Facebook privacy

Carmi Levy | Wide Angle Zoom: If an insurance company learns something interesting about its client through the Internet, is that snooping?

Microsoft 'worked with Apple' for Silverlight on iPhone, says Goldfarb

By not making such a big deal out of trying to stream video to the iPhone, Microsoft got a big deal out of it, revealed the Silverlight product manager.

Clicker.com cuts through the Web video chaos

In a world where homemade video and Hollywood movies travel the same pipeline, it's good to have a real search engine to cut through the clutter.

A case study in improving software: What Office 2010 can learn from Notion 3

A music composition product gambles with a complete overhaul, in an effort to make headway against two well-known competitors in a tough market.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.