Heraldnet.com
THURSDAY, NOVEMBER 12, 2009 1:44 am
LocalNorthwestNation & WorldPoliticsSpecial ReportsPhotosColumnistsMultimedia 
Blog
Amy Rolph
Report shows optimism up, jobs down
Blog
Amy Rolph
Forward Mobility moves on in $100,000 contest
Your town news
Mike Benbow
Business editor Mike Benbow's insights into all things business.
•Latest: Extended tax credit should spur home sales
Steve Tytler
Steve Tytler answers your questions about real estate.
•Latest: Forecast for 2010 housing market: slow decline
 
WEEK IN REVIEW
Wednesday
Student hit in crosswalk to return
81 veterans' names, 81 meaningful lives honored...
USO singer's voice still charms them in Edmonds
Tuesday


Fire destroys Emory's restaurant
Peggy Pritchard Olson always put Edmonds first
Camano Island burglaries spike: Is Colton back?
Monday


Tree clearing, mud slide angers Everett neighbor
Later start for school day unlikely in Marysville
Hopes for Snohomish excursion train may hinge o...
Sunday


Glacier Peak freshman overcomes jitters to win ...
Gay marriage issue can wait, say Referendum 71 ...
Cities across south Snohomish County see tax re...
Saturday


Thousands honor slain Seattle police officer Ti...
Suspect identified in Seattle police killing
Mountlake Terrace thrilled by high school's fir...
Friday


Officer Timothy Brenton. Gone, but not forgotten
Person sought in officer's killing is shot in head
Thousands to pay respects to slain Seattle poli...
Thursday


Tale of 1916 Everett Massacre retold in style o...
Reservist survived Iraq but not his return to c...
Swine flu suspected in infant’s death
 

ADVERTISEMENT

Business   Print This Article  Email This Page  Subscribe Now! facebook digg reddit del.icio.us fark stumble

Associated Press  (click to enlarge)
Dan Kaminsky is director of penetration testing for Seattle-based computer security consultant IOActive Inc.
 
ADVERTISEMENT

 
CONTACT THE HERALD
Mike Benbow, Business Editor
benbow@heraldnet.com
 
Published: Sunday, August 10, 2008

Scams thrive in Net security hole

SAN FRANCISCO -- A giant vulnerability in the Internet's design allows criminals to silently redirect traffic to Web sites under their control. The problem is being fixed, but its extent remains unknown and many people are still at risk.

The gaping security hole enables a scam that targets ordinary people typing in a legitimate Web address. It happens because hackers are now able to manipulate the machines that help computers find Web sites. If the trick is done properly, computer users are unlikely to detect whether they've landed at a legitimate site or an evil double maintained by someone bent on fraud.

Security experts fear an open season for virus attacks and identity-fraud scams.

"It's kind of like saying, 'There's a bunch of money on the street. If you can get over there soon enough, you can get it,' " said Ken Silva, chief technology officer for VeriSign Inc., which manages the ".com" and ".net" directories of Internet addresses. "It's something the industry is taking seriously. You'd be in a bad place if you weren't doing something about it."

The bug's existence was revealed nearly a month ago. Since then, criminals have pulled off at least one successful attack, directing some AT&T Inc. Internet customers in Texas to a fake Google site. The phony page was accompanied by three programs that automatically clicked on ads, with the profits for those clicks flowing back to the hackers.

There are likely worse scams happening that haven't been discovered or publicly disclosed by Internet service providers. "You can bet that the (Internet providers) are going to stay tight-lipped about any attacks on their networks," said HD Moore, a security researcher.

The AT&T attack probably would have stayed quiet had it not affected the Internet service of Austin, Texas-based BreakingPoint Systems Inc., which makes machines for testing networking equipment and has Moore as its labs director. He disclosed the incident in hopes it would help uncover more breaches.

The underlying flaw is in the Domain Name System (DNS), a network of millions of servers that translate words typed into Web browsers into numerical codes that computers can understand.

Getting from one place to another on the Internet typically requires a trip through several DNS servers, including some that accept incoming data and store parts of it. That opens them up for potential attack.

What this means is that a computer user in say, San Francisco, might type www.yahoo.com and head straight to the real Yahoo site, while at the same moment, a user in New York -- whose traffic is routed through different DNS servers -- might type that same Web address and end up on a phony duplicate site.

Scant details have been available about how the vulnerability works.

The researcher who discovered it, Dan Kaminsky of Seattle-based computer security consultant IOActive Inc., announced July 8 that he'd found a major weakness in DNS. But he kept the rest secret because he wanted to give companies that run vulnerable servers a month to apply patches -- software tweaks that cover the security hole. He coordinated with Microsoft Corp., Cisco Systems Inc., Sun Microsystems Inc. and other major vendors to simultaneously issue patches.

1. Emory’s owner fears fire was arson
2. Monroe honking case makes it to state Supreme Court
3. Vatican ponders the souls in space
4. 81 veterans' names, 81 meaningful lives honored in Snohomish
5. Hope dims that Olympics will boost region
6. Student hit in crosswalk to return
7. Smokey Point to celebrate end of roadwork
8. Death on Edmonds waterfront ruled a suicide
9. Help for young moms may continue
10. Semifinal slate sealed on ‘Dancing With Stars’
Enterprise Newspaper Snohomish County Business Journal
Bazaar Fever
Hawks proud of historic season
Olson always put Edmonds first
Honoring student veterans
‘Wheedle' author comes to Lynnwood bookshop
Mavs build early lead en route to easy win
Prep football games of the week (state playoffs)
Tears of laughter, tears of grief
Death on Edmonds beach likely a suicide
The Enterprise Online Newspaper


20% Off Dinner
Up to $75 Value!

15% Off Your
First Time Purchase

25% off Bath & Groom
New Customers

Lube, Oil & Filter
Buy 1 - Get 1 FREE

$2 OFF
at Box Office

FREE Appetizer with any
purchase daily 2-6pm

20% off Click Here*
Buy 1 Offer Click Here*

Family Night Free Sundae
$9.99 Prime Rib

All you can Eat Buffets
Angel of the Winds

$1 off French Dip
$4.99 Burger Basket

QuadraFire Save $250
Free Smart-Stat

50% off 2nd Pizza
Special Click Here!

FREE Appetizer w/
purchase of 2 entrees

Great Food
24 Hours a Day

FREE 6 lb. Pad w/
30yd Carpet Purchase

Come and Relax
Monthly Specials

$5 Off
Stylecut

$5 OFF
Lunch or Dinner

Pacific Northwest
Fresh Cuisine

Free Dessert!
Click here!

Buffet Dining
Tulalip Resort

Island Flavors with
Finest NW Ingredients

Free Garlic Bread/Free Soda
Click here for details!

FREE Appetizer with any
purchase daily 2-6pm
Shawn O'Donnell's
TODAY'S TOP JOBS
 View All Top Jobs 
Top Cars
Top Homes

ADVERTISEMENT