‘Core’ flaw in internet security threatens email and website navigation

A newly discovered flaw in the internet’s core infrastructure not only permits hackers to force people to visit websites they didn’t want to, it also allows them to intercept email messages, according to the researcher who discovered the bug.

Considering the silent nature of the attack and the sensitive nature of much electronic correspondence, the potential for damage from this second security flaw is high. But there’s no evidence yet this method of targeting email has been used in a successful attack.

Dan Kaminsky of Seattle- based security consultant IOActive Inc exposed a giant vulnerability in the internet’s design that, in one case, allowed hackers to re-route computer users ito a fake Google.com site loaded with automated advertisement-clicking programmes — a scam to generate profits for the hackers from those clicks.

The flaw wasn’t in the site itself but in back-end machines responsible for guiding computers to that site.

The vulnerability Kaminsky found is especially insidious as it allows criminals to tamper with machines whose reliability and trustworthiness is critical for the internet to function.

Kaminsky has given few details publicly about the vulnerability he found in the Domain Name System (DNS), a network of servers used to connect computers to websites. He remained tightlipped so that internet providers would have time to fix their machines. Many have done so, but others have delayed, leaving some people at risk.

Major operators like Microsoft, Cisco, Sun and others have issued patches — software tweaks that cover the security hole and prevent affected machines from ingesting bogus data hackers are trying to feed them.

“The industry has rallied like we’ve never seen it rally before,” Kaminsky said.

One of the flaws Kaminsky found was the susceptibility of many email servers to the DNS vulnerability, an opening that gives criminals a way to plant themselves in the middle of the transmission from the sender to the recipient and redirect messages to their own servers.

The result — criminals have a way not only to comb the contents of those messages, but also to gain access to other password-protected sites.

The thrust of the DNS flaw is that it allows hackers to attach bad information to packets of data flowing in and out of DNS servers so they change the directions they give to websites.

It’s the equivalent of turning around a street sign to send drivers down the wrong street.

More in this section

Lunchtime News

Newsletter

Get a lunch briefing straight to your inbox at noon daily. Also be the first to know with our occasional Breaking News emails.

Cookie Policy Privacy Policy Brand Safety FAQ Help Contact Us Terms and Conditions

© Examiner Echo Group Limited