| |||||||
| Slashdot RSS RSS news feed directly from Slashdot. |
![]() |
| | LinkBack | Thread Tools | Display Modes |
| | #1 (permalink) | |
| Monley writes "Help Net Security is running a story about a severe flaw in BIND's implementation that allows fraudsters to efficiently predict generated random numbers without the need to control the route between the user and the DNS server. (Here are HTML and PDF versions of the paper.) Using this vulnerability, fraudsters can remotely forge DNS responses and direct users to fraudulent websites, which can steal the user's sign-in credentials and do other mischief. The flaw was discovered by security researcher and Trusteer's CTO, Amit Klein." The ISC has released a patch to BIND 9. Read more of this story at Slashdot. More... | ||
| | | |
| Sponsored Links |
![]() |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Ars Technica // Attack of the "evil twin" WiFi networks | Gizmo | Ars Technica RSS | 0 | 26-April-07 03:50 AM |
| Slashdot // "Market Share" "Installed Base" and Consumer Electronics | Gizmo | Slashdot RSS | 0 | 18-March-07 12:30 PM |
| Ars Technica // Cable and phone companies call Net neutrality "silly," "mumbo jumbo" | Gizmo | Ars Technica RSS | 0 | 07-September-06 10:01 PM |
| Ars Technica // CEA: RIAA refuses to cooperate, carries out "thinly veiled attack" on fair use | Gizmo | Ars Technica RSS | 0 | 14-August-06 06:01 PM |
| Ars Technica // CEA: RIAA refuses to cooperate, carries out "thinly veiled attack" on fair use | Gizmo | Ars Technica RSS | 0 | 10-August-06 06:09 PM |