Heraldnet.com
SATURDAY, JULY 4, 2009 11:54 am
LocalNorthwestNation & WorldPoliticsSpecial ReportsPhotosColumnistsMultimedia 
Blog
Michelle Dunlop
Tests continue on Boeing's 787
Your town news
Mike Benbow
Business editor Mike Benbow's insights into all things business.
•Latest: State's new commerce director shares his business principles
Steve Tytler
Steve Tytler answers your questions about real estate.
•Latest: New rules create an appraisal nightmare
 
WEEK IN REVIEW
Friday
Armed man shot by deputies in Arlington
Police ID make of vehicle in fatal hit-and-run
Boeing's 6-month tally: 1 net order
Thursday


One fire rips through $2 million home, another ...
Swine flu claims 2nd victim in Snohomish County
Jetty Island firefight continues; hot weather ...
Wednesday


Fire District 1 negotiates to take over service...
Snohomish County population rising fast since 2...
Honey's owners indicted by feds
Tuesday


Mobile home tenants along Snohomish River told ...
Lincoln to leave Everett in 2013
Put on your sailor's cap and explore Naval Stat...
Monday


Disabled people will be left without a ride
You'll soon have 4,500 reasons to trade in that...
Pay hike deserved, Monroe chief says
Sunday


1,670 local students in county are without homes
Monroe's business gets done in secret
$9 million to be sought for U.S. 2 in federal t...
Saturday


Use of local parks spikes
Gay-friendly shift at 2 churches
Racist graffiti scrawled on cars in Everett nei...
 

ADVERTISEMENT

Business   Print This Article  Email This Page  Subscribe Now! facebook digg reddit del.icio.us fark stumble

Associated Press  (click to enlarge)
Dan Kaminsky is director of penetration testing for Seattle-based computer security consultant IOActive Inc.
 
ADVERTISEMENT

 
CONTACT THE HERALD
Mike Benbow, Business Editor
benbow@heraldnet.com
 
Published: Sunday, August 10, 2008

Scams thrive in Net security hole

SAN FRANCISCO -- A giant vulnerability in the Internet's design allows criminals to silently redirect traffic to Web sites under their control. The problem is being fixed, but its extent remains unknown and many people are still at risk.

The gaping security hole enables a scam that targets ordinary people typing in a legitimate Web address. It happens because hackers are now able to manipulate the machines that help computers find Web sites. If the trick is done properly, computer users are unlikely to detect whether they've landed at a legitimate site or an evil double maintained by someone bent on fraud.

Security experts fear an open season for virus attacks and identity-fraud scams.

"It's kind of like saying, 'There's a bunch of money on the street. If you can get over there soon enough, you can get it,' " said Ken Silva, chief technology officer for VeriSign Inc., which manages the ".com" and ".net" directories of Internet addresses. "It's something the industry is taking seriously. You'd be in a bad place if you weren't doing something about it."

The bug's existence was revealed nearly a month ago. Since then, criminals have pulled off at least one successful attack, directing some AT&T Inc. Internet customers in Texas to a fake Google site. The phony page was accompanied by three programs that automatically clicked on ads, with the profits for those clicks flowing back to the hackers.

There are likely worse scams happening that haven't been discovered or publicly disclosed by Internet service providers. "You can bet that the (Internet providers) are going to stay tight-lipped about any attacks on their networks," said HD Moore, a security researcher.

The AT&T attack probably would have stayed quiet had it not affected the Internet service of Austin, Texas-based BreakingPoint Systems Inc., which makes machines for testing networking equipment and has Moore as its labs director. He disclosed the incident in hopes it would help uncover more breaches.

The underlying flaw is in the Domain Name System (DNS), a network of millions of servers that translate words typed into Web browsers into numerical codes that computers can understand.

Getting from one place to another on the Internet typically requires a trip through several DNS servers, including some that accept incoming data and store parts of it. That opens them up for potential attack.

What this means is that a computer user in say, San Francisco, might type www.yahoo.com and head straight to the real Yahoo site, while at the same moment, a user in New York -- whose traffic is routed through different DNS servers -- might type that same Web address and end up on a phony duplicate site.

Scant details have been available about how the vulnerability works.

The researcher who discovered it, Dan Kaminsky of Seattle-based computer security consultant IOActive Inc., announced July 8 that he'd found a major weakness in DNS. But he kept the rest secret because he wanted to give companies that run vulnerable servers a month to apply patches -- software tweaks that cover the security hole. He coordinated with Microsoft Corp., Cisco Systems Inc., Sun Microsystems Inc. and other major vendors to simultaneously issue patches.

1. Snohomish County man dies of swine flu
2. Lynnwood bank reprimanded by government
3. Police ID make of vehicle in fatal hit-and-run
4. Armed man shot by deputies in Arlington
5. IRS joins puppy mill investigation
6. Jetty Island ready for sand castles
7. Boeing's 6-month tally: 1 net order
8. Warriors & Patriots: Many American Indians served before getting full citizenship rights
9. Movin' out
10. Marshals seize swindler's home
Enterprise Newspaper Snohomish County Business Journal
Warriors looking for balance
Three Scots vying for QB slot
Jackson looks for another title
Decorated veteran continues to serve as active volunteer
City Council reviewing sign regulations
Wildcats get a peek at newcomers
Lynnwood still in rebuilding mode
Shoreline feels a kindergarten growth spurt
Leave the patriotic pyrotechnics to professionals, cities urge
The Enterprise Online Newspaper

TODAY'S TOP JOBS
 View All Top Jobs 
Top Cars
Top Homes


ADVERTISEMENT