DNS Attack Writer a Victim of His Own Creation
BobB writes "HD Moore has been owned. Moore, the creator of the popular Metasploit hacking toolkit, has become the victim of a computer attack. It happened on Tuesday morning, when Moore's company, BreakingPoint, had some of its Internet traffic redirected to a fake Google page that was being run by a scammer. According to Moore, the hacker was able to do this by launching what's known as a cache poisoning attack on a DNS server on AT&T's network that was serving the Austin, Texas, area. One of BreakingPoint's servers was forwarding DNS (Domain Name System) traffic to the AT&T server, so when it was compromised, so was HD Moore's company."
I wonder if, when he got attacked, he just leaned back in his big leather chair, and chuckled, "Well played, sir, well played."
The reporter has published a correction, which is also reflected on the Metasploit Blog.
Well, all I can say is, no one, not even him can prevent this shit from happening if a server out of their control such as this is unpatched. He should give at&t hell. All the other big ones like comcast and verizon claim to be fully patched. I understand the size of at&t's network but this is no excuse when everyone uses your network and pays good money for it.
Serves him right.
There is no "-1 offended" or "-1 you don't agree with me" mod options for a reason.
Since the attack wasn't on BreakingPoint, but rather than upstream DNS server, he pretty much just got swept up in the dragnet. These kind of attacks seem scarier than a direct attack, since you can do "everything right" with regard to patching, updating, firewalling, etc, and still get owned.
"Can't you see that everyone is buying station wagons?"
http://www.pcworld.com/businesscenter/article/149136/dns_attack_writer_a_victim_of_his_own_creation.html
This is real irony. So, if someone tags this story "irony", he would be correct.
Knowledge is power. Knowledge shared is power lost.
For tis the sport to have the engineer hoist with his own petard.
Really this proverb is best portrayed by the timeless coyote chasing the road runner cartoons.
It's interesting to see how widespread this exploit has become. I've checked my home and office connections using Dan Kaminsky's handy DNS Checker and it appears that my ISPs have taken measures to avoid this problem.
Unfortunately, I also travel a good deal for work, and it's hard to be sure that the ISP used by whatever-hotel-I'm-staying-at-this-week will be as proactive.
The guys in TFA got pwned by being redirected to a bogus Google look-alike page. As I understand it, this kind of attack would be noticeable when attempting to use a secure (HTTPS) web connection, because the browser should throw up a certificate error. Is this true? What other ways might be used to detect this problem?
Yeah.. it'd be more like the US getting attacked by weapons they made and sold to Iraq or something... oh hang on..
Well, if all the posts are filled with mindless, off-topic dribble about how, in Soviet Russia, we welcome the opportunity exploit Natalie Portman's hot grit-pouring overlords with our vulnerable DNS servers, then it's a safe bet your on slashdot.
Saying #1: Jesus to Peter after Peter had sliced the ear off of the slave Malchus.
Saying #2: ????
Saying #3: Galatians 6:7... though I was really tempted to say PROFIT!!!
This DNS test is much better. https://www.dns-oarc.net/oarc/services/dnsentropy
The problem is that bad DNS responses should not be a source of vulnerability. Anytime there is traffic outside of your trusted domain, the identity of the remote system should not be trusted without a secure connection. There is work on Secure DNS, but I think it is better just to consider DNS unreliable, especially since wireless access points are common, and can give you whatever DNS they want. Even if you use another DNS server, it is easy enough to override it at the router. Unencrypted traffic should always be considered untrusted and prone to hacking. We need a system of secondary (tertiary, etc?) certificate signing so that every web site doesn't have to pay for a commercially signed certificate. That is more efficient and reliable than Secure DNS. (Right?)