Warning this article may contain opinions of the author that you and iTWire don't agree with.
Visit the last page to have your say in our forum.

No. 1 Story

Telstra adds one million mobile services, but Sensis plummets

Telstra has revealed the addition of almost one million new mobile services in the six months to December 2011, but Sensis revenues plummeted 24 percent in 12 months.

read more

Has Apple really fixed its BIND?

Opinion and Analysis

Security Update 2008-005 for Mac OS X 10.4.11 and 10.5.4 includes a newer version of BIND to overcome the DNS poisoning flaw. But questions are being asked about whether the update really does protect against this issue.

Swa Frantzen of the SANS Internet Storm Center asserts that a patched installation of 10.5.4 still uses incrementing port numbers for DNS resolution, one of the characteristics that makes the attack feasible.

"Apple might have fixed some of the more important parts for servers, but is far from done yet as all the clients linked against a DNS client library still need to get the workaround for the protocol weakness," wrote Frantzen.

nCircle's Andrew Storms makes the same observation about 10.5.4.

"The current countermeasure to this DNS cache poisoning vulnerability is to introduce increased entropy by forcing randomization of the query ID and the source port," he wrote.

"Essentially, making it all the more difficult to spoof the DNS response. However, it appears that Apple forgot something. The client libaries on my OSX 10.4.11 system, post patch install, still does not randomize the source port."

Both researchers appear to have only tested the normal 'client' version of Mac OS X. But according to some experts, the fix is really only significant for the server versions of Apple's operating system. For example, "patching BIND is really not a worry on most Mac installs," wrote an unidentified member of the Rixstep team.

So what's going on? The story continues on page 2.



- sponsored feature -

The Death of Traditional BI: What’s Next?

How to Make Business Discovery Work for Your Business IP PABX BUYING GUIDE

Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more