Network World
Thursday, January 8, 2009
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community

Navigation

Researcher demos at RSA how firewalls can be penetrated via DNS

A security researcher Tuesday at the RSA Conference is going to demonstrate how routers from Linksys and other manufacturers can be abused by attackers to penetrate firewalls. According to a story by the IDG News Service, Dan Kaminsky has spent the past year studying how design flaws in the way that browsers work with the Internet's Domain Name System (DNS) can be manipulated in this way.

According to the story:

The technique, called a DNS rebinding attack, would work on virtually any device, including printers, that uses a default password and a Web-based administration interface, said Kaminsky, who is director of penetration testing with IOActive.

Although security researchers had known that this type of hack was theoretically possible, Kaminsky's demo will show that it can work in the real world, the story adds.

More from Cisco Subnet:

* Lost memo of missing Cisco sales trainee found in Galactica
Riverbed is just another has-been Cisco competitor
Don't split that OSPF area
Services, collaboration are key themes of this year’s Cisco Summit
* CCNP lab essentials
* Jeff Doyle: Understanding MPLS

Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more.

- 20 useful sites for Cisco networking professionals
- This month's Cisco Subnet giveaways
- Network World's IT Buyer's Guide: Cisco products

- Subscribe to Network World's Cisco Alert, which includes a weekly digest of all Cisco Subnet items

Click to read the article this is in response to.

Reply

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: