Welcome Back To IDN Forums - International Domain Name Forums - we are an Adsense Revenue Sharing Forum
IDN Forums - IDN Domains
IDN Domains
 

Go Back   IDN Forums - IDN Domains > General Domains > General Domain Names Discussion
User Name
Password


Reply
 
Thread Tools Display Modes
  #1  
Old 04-29-2006, 02:20 AM
mulligan's Avatar
mulligan mulligan is offline
ドメイン名.ws
 
Join Date: Jan 2006
Posts: 2,282
Rep Power: 0
mulligan is an unknown quantity at this point
Big holes in net's heart revealed

Quote:
Simple attacks could let malicious hackers take over more than one-third of the net's sites, reveals research. The finding was uncovered by researchers who analysed how the net's addressing system works.
They also found that if the simple attacks were combined with so-called denial-of-service attacks, 85% of the net becomes vulnerable to take-over.
The researchers recommended big changes to the net's addressing system to tackle the vulnerability at its heart.
Site seizing
When you visit a website, such as news.bbc.co.uk, your computer often asks one of the net's address books, or domain name servers, for information about where that site resides.
But the number of computers that have to be consulted to find the computers where that site is located often makes sites vulnerable to attack by vandals and criminals, found Assistant Professor Emin Gun Sirer and Venugopalan Ramasubramanian from the Department of Computer Science at Cornell University.
Professor Sirer told the BBC News website that, on average, 46 computers holding different information about the components of net addresses are consulted to find out where each dotcom site is actually hosted.
But, he said, this chain of dependencies between the computers that look after the different parts of net addresses creates all kinds of vulnerabilities that clever hackers could easily exploit.
"The growth of the internet has caused these dependencies to emerge," said Professor Sirer. "Instead of having to compromise one you can compromise any one of the three dozen."
All the information gathered and analysed by the researchers has to be publicly available to keep the net's addressing system working. The research analysed information about almost 600,000 computers.
The research also revealed that 17% of the servers that host the net's address books are vulnerable to attack via widely known exploits.



"Because of these dependencies about one-third of the net's names are trivially compromisable by script kiddies," he said.
One site vulnerable in this way was run by the FBI, said Professor. Sirer. Although the five computers that act as the first reference point for the fbi.gov domain were secure, one of the five that connect to these has yet to install a patch for a well-known bug.
That computer was fixed after the Cornell team reported its findings to the FBI, but hundreds of thousands of sites suffer from similar problems.
The most vulnerable net domain found by the survey was that of the Roman Catholic Church in the Ukraine.
Criminals such as phishing gangs would be interested in re-directing traffic from well-known sites so they can grab key login and personal details that would help them de-fraud web users.
If attacks via known exploits were combined with other attacks, said Professor Sirer, malicious hackers could open up enormous amounts of the net to attack.
For instance, he said, hackers could use denial-of-service attacks to overwhelm the net address books that are secure. This could leave users' computers with no choice but to look up website names via compromised servers.
By combining well-known attacks and denial-of-service attacks, 85% of the net's domains become vulnerable to take over, revealed the analysis.
He said: "They could already be doing it and we would hardly ever know."
The research had exposed a big problem that net administrators need to tackle, said Professor Sirer. Thought should be given to using a secure version of the system used to pass around information about net addresses.
"The domain name system has been incredibly successful so far but it is showing its age," he said. "We need to re-think the entire naming infrastructure of the internet."
The hierarchical structure of the net's address books could be replaced with a more resilient system, he said, that uses a peer-to-peer type structure that would be harder to compromise.


http://news.bbc.co.uk/2/hi/technology/4954208.stm




__________________
元.net | 米.net | 宮.net | 白.net | 華.net | 八.tv | 蘭.net | 馬.net | 安.net | 牛.net | я.net | ン.net | 灶.com
無料壁紙.jp ~ Free Wallpaper ~ Reasonable offers considered
IDNPool.com ~ Domain Portfolio
Transactions not completed within 7 days from end of sale/auction are void
Reply With Quote
Sponsored Links
  #2  
Old 04-29-2006, 03:05 AM
yanni's Avatar
yanni yanni is offline
Senior Member
 
Join Date: Feb 2006
Posts: 1,238
Rep Power: 4
yanni is on a distinguished road
Re: Big holes in net's heart revealed

"The domain name system has been incredibly successful so far but it is showing its age," he said. "We need to re-think the entire naming infrastructure of the internet."


Uh-oh!
__________________
I sale worthless idn.
Reply With Quote
  #3  
Old 04-29-2006, 03:19 AM
Giant Giant is offline
Senior Member
 
Join Date: Dec 2005
Location: Canada
Posts: 1,685
Rep Power: 0
Giant is an unknown quantity at this point
Re: Big holes in net's heart revealed

Quote:
Originally Posted by yanni
"The domain name system has been incredibly successful so far but it is showing its age," he said. "We need to re-think the entire naming infrastructure of the internet."

Uh-oh!

"naming infrastructure" can be changed, and it won't change the nature of names. Humans still need names, and names are still representing IPs. Even Puny Code is changed to Horse Code, the names we hold are still valid.
__________________
@

Dot Com is King, IDN.com will be king. ccTLD will be queen.

@
Reply With Quote
  #4  
Old 04-29-2006, 01:03 PM
Rubber Duck's Avatar
Rubber Duck Rubber Duck is offline
Premium Member
 
Join Date: Sep 2005
Location: United Kingdom
Posts: 10,927
Rep Power: 13
Rubber Duck is on a distinguished road
Re: Big holes in net's heart revealed

Quote:
Originally Posted by Giant
"naming infrastructure" can be changed, and it won't change the nature of names. Humans still need names, and names are still representing IPs. Even Puny Code is changed to Horse Code, the names we hold are still valid.

Got it in one. Sites need to be identified by computers using IPs. Domain Names are simply Aliases, but they are essential. If you change the IP address for techinical reasons you simply cannot update millions of users each time, so even if human could remember the IP address due to some chip implanted in their skull they would still need domain names. The only way to rationalise the domain name system would be to kick the extensions into touch as has been suggest by many of the intellectually challenged at DNFs. The fact is that would remove much of the scope for expanding an already tight domain structure, unless the names actually became the extensions and the domain owners became registries renting sub-domains. Sound like a recipe for disaster from where I am standing. No, the truth is the current naming system is about at good as it gets and legal ramnifications for changing it are unthinkable. The only alteration I can see of any note is the introduction of extensionless universal keywords that might be rented out in a similar way to Premium.tv.

The problem with this industry is that everyone follows the frothy news stories that come out every week, but most can see the very real changes that are going on almost unnoticed. They are much more interested in pixel marketing!
__________________
Premium Domains, large selection of most of the heavily speculated languages. PM me for details.

All offers over 1 week old are null and void.

dnlocal.com
Reply With Quote
  #5  
Old 04-29-2006, 04:15 PM
jose's Avatar
jose jose is offline
Senior Member
 
Join Date: Jan 2006
Posts: 2,058
Rep Power: 5
jose is on a distinguished road
Re: Big holes in net's heart revealed

This is hype. The unsecure dns servers must already be patched by now and you can't DOS ALL the other dns servers at the same time. Zombie networks are decresing in size due to the increase of computers with firewalls and winupdated.

And... in case of a sucessfull attack it would not last for long and they wouldn't be "taking over" anything, lol. Hype and more hype.
__________________
Négoce.com
Tous les négoces en ligne

Have some social domains? Check the Highest Payouts on the Internet -> $80 per sign-up!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump




Powered by vBulletin Version 3.5.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 2.4.5
Style Design By: Resourcelabz.se
Copyright Urban Japan, Inc. 2005, 2006


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99