DNS Sploit Weaponization

4

Author: Dave Lewis

Yeah, a little dramatic

So, unless you’ve been hiding under a rock for the last little while you’ll know that Dan Kaminsky broke DNS in a rather big way.

And you’d know that the gory details hit the tubes of the internet a couple days ago.

Hell, there was even a poem about the whole mess. (bless you Hoff)

Now, the DNS ’sploit has been weaponized. HD Moore and company over at Metasploit have released it. For a full write up on it check out our friend, Nate McFeter’s, blog posting on the DNS exploit. Yes, it is being actively exploited.

This storm has of course reignited the inevitable (and tiresome) disclosure debate. Let me save you the trouble and cut right to the chase…

PATCH YOUR FSCKING DNS SERVERS.

Consider yourselves warned…again.

OK, I’m tired talking about this subject. What else is going on in the world?

Tags: , , , , ,

Tag It:
  • Digg
  • del.icio.us
  • Slashdot
  • Technorati
  • SphereIt
  • StumbleUpon
  • NewsVine
  • LinkedIn
  • TwitThis
  • Facebook
  • Live

Comments

4 Responses to “DNS Sploit Weaponization”
  1. Thanks for the coverage gents! Further, thanks for the link about HD’s tweets. If you don’t mind, might link back to you with my blog with a quick update on HD’s comments.

  2. Dave Lewis says:

    @Nate

    Not a problem mate. Feel free.

    Have a great weekend.

  3. Security4all says:

    So there is indication of real exploitation after all.

  4. andar909 says:

    hi, andar here, i just read your post. i like very much. agree to you, sir.

Speak Your Mind

Tell us what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!