DNS Poisoning On The Rise

Moderators: Moderator, Global Moderator

Post Reply
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

DNS Poisoning On The Rise

Post by Tami »

DNS Poisoning On The Rise: Report
By JACK KAPICA

Writers of malicious code are jumping on the latest way to subvert the Internet called "DNS poisoning," an Internet security company says.

The number and severity of attacks on Domain Name Service servers have risen sharply on networks around the globe, reports Sandvine Inc., based in Waterloo, Ont.

With DNS poisoning, an attacker taints the server's cache, a form of memory that computers use to speed up connections to frequently visited sites. "Poisoning" involves placing incorrect routing information in the cache, so that illegitimate sites appear in a browser even if a surfer requested a legitimate Web address.

One successful poisoning could affect thousands of users and result in many Internet users being taken to sites that bilk them of their personal information, steal their identity, download malicious software (worms, spyware or adware) onto their computers, or bombard them with irrelevant advertisements. This can happen even though people typed in the correct address into their browsers or followed the right hyperlinks.

The practice is favoured by phishers, pharmers and other malicious code writers who depend on luring the unwary to sites designed to separate surfers from their passwords, credit-card numbers and other personal information.

Poisoning can be accomplished by individual computers or by networks of "zombie" computers — home computers that have been infected to operate without the owners' knowledge.

The Sandvine Security Operations Services team identified increases in attacks in which single attackers performed more than 1,000 times the normal amount of lookups on a DNS server within a 12-hour period.

The damage is compounded for broadband service provider networks. DNS attacks are responsible for overwhelming DNS servers to the point of failure, causing wide-scale service outages. This can cost millions of dollars in subscriber refunds, not to mention the substantial financial burden of trying to identify and alleviate the problem.

"Attacks and malicious code are becoming more and more evasive and targeted," Sandvine vice-president Don Bowman said in a statement. Service providers need to ... monitor their networks for threats and respond in real time to shut down these attacks."

[url=\"http://www.globetechnology.com/servlet/story/RTGAM.20050524.gtpoisonmay24/BNStory/Technology/\"]source: Globe Technology[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “Security”