ICANN/GNSO GNSO Email List Archives

[ga]


<<< Chronological Index >>>    <<< Thread Index >>>

Re: [ga] Details of DNS Flaw Leaked; Exploit Expected by End of Today

  • To: "Prophet Partners Inc." <Domains@xxxxxxxxxxxxxxxxxxx>
  • Subject: Re: [ga] Details of DNS Flaw Leaked; Exploit Expected by End of Today
  • From: "Jeffrey A. Williams" <jwkckid1@xxxxxxxxxxxxx>
  • Date: Tue, 22 Jul 2008 01:53:50 -0700

Ted,

  Your only a week behind the curve.  This information was posted
to this forum nearly a week ago now.

"Prophet Partners Inc." wrote:

> http://blog.wired.com/27bstroke6/2008/07/details-of-dns.html "Despite
> Dan Kaminsky's efforts to keep a lid on the details of the critical
> DNS vulnerability he found, someone at the security firm Matasano
> leaked the information on its blog yesterday, then quickly pulled the
> post down. But not before others had grabbed the information and
> reposted it elsewhere, leading Kaminsky to post an urgent 0-day
> message on his blog reading, "Patch. Today. Now. Yes, stay late."
> Hackers are furiously working on an exploit to attack the
> vulnerability. HD Moore, creator of the Metasploit tool, says one
> should be available by the end of the day. Earlier this month,
> Kaminsky, a penetration tester with IOActive, went public with
> information about a serious and fundamental security vulnerability in
> the Domain Name System that would allow attackers to easily
> impersonate any website -- banking sites, Google, Gmail and other web
> mail websites -- to attack unsuspecting users." If ICANN hasn't done
> so already, it would be wise to immediately notify all ICANN
> registries and registrars about the exploit and the urgency to
> implement the security patches. Sincerely,
> Ted
> Prophet Partners Inc.
> http://www.ProphetPartners.com
> http://www.Premium-Domain-Names.com

Regards,

Spokesman for INEGroup LLA. - (Over 281k members/stakeholders strong!)
"Obedience of the law is the greatest freedom" -
   Abraham Lincoln

"Credit should go with the performance of duty and not with what is
very often the accident of glory" - Theodore Roosevelt

"If the probability be called P; the injury, L; and the burden, B;
liability depends upon whether B is less than L multiplied by
P: i.e., whether B is less than PL."
United States v. Carroll Towing  (159 F.2d 169 [2d Cir. 1947]
===============================================================
Updated 1/26/04
CSO/DIR. Internet Network Eng. SR. Eng. Network data security IDNS.
div. of Information Network Eng.  INEG. INC.
ABA member in good standing member ID 01257402 E-Mail
jwkckid1@xxxxxxxxxxxxx
My Phone: 214-244-4827




<<< Chronological Index >>>    <<< Thread Index >>>