Warning this article may contain opinions of the author that you and iTWire don't agree with.
Visit the last page to have your say forum.
PDFPrintE-mail

Apple in a bind over BIND

Opinion and Analysis

I've criticised Apple before for being slow to deliver patched versions of open source and other third-party software, but the latest example involving BIND, the software that provides DNS services, is hard to fathom.

Other vendors, including Microsoft and Cisco, released DNS patches earlier this month to protect their customers from the risk of Internet traffic being diverted to malicious servers. Apple's delay means users at sites running Mac OS X Server are still vulnerable to this attack.

Earlier this year, security researchers discovered a weakness in DNS protocols and implementations. DNS (Domain Name System) is the mechanism that converts human-friendly domain names such as www.itwire.com to numeric IP addresses such as 192.168.0.1.

The weakness could be used relatively easily by an attacker to 'poison' (maliciously change) the list of name-to-number mappings already established by a system.

The danger is that users would then be invisibly redirected to web sites other than those they intended to visit. This situation could be used for phishing (capturing people's account credentials for Internet banking and other sites involving value) or to lure visitors to servers loaded with malware that is silently transferred along with the web page (more a problem with Windows than other operating systems).

In a co-ordinated effort, most major vendors released fixes for affected software earlier this month. That included an update for Internet Systems Consortium's BIND, which is the most widely used DNS server.

So where is Apple's update? Please read on.



SPONSORED PRESS RELEASES

Axway cautions on escalating risks and cost of file transfer
By John Lee, Regional Sales, Pacific, Axway Inc

Featured IT jobs

Senior Software consultant responsible for providing support on a unique enterprise level software solution for various customers, Melbourne based!
Skills Tags:   IT  ITIL  Linux  Management  RFP  Unix
This financial client has an excellent opportunity for an experienced Database Developer. SQL 2005 Some Schema design + SSIS & SSRS - 80k+super
Skills Tags:   Design  Development  SQL  SQL Server
Massive Hyperion Project requires a Hyperion Planning Architect / Lead Developer - drive home a huge Hyperion solution.
Skills Tags:   Architect  Design  Development  Hyperion
OBIEE Consultant to work on a very large greenfield OBIEE implementation to date to work end-to-end with excellent modelling & BI Server skills
Skills Tags:   Business Intelligence  Cognos  Hyperion  Informatica  Oracle  SQL

Editors Picks

Stories you may have missed 

What iTWire offers for free

E - mail News SMS Headlines Desktop Alerts News Feeds Job Alerts Technology Events Press-Releases