SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Information Architecture >> Databases

SecTor event highlights holes in DNS, databases

SecTor event highlights holes in DNS, databases

By:  Kathleen Lau  On: 21 Nov 2007 For: ComputerWorld Canada Creator

The inaugural version of a Toronto-based security conference showcases experts who explain rebinding attacks on domain name servers and how to stop them. Plus: SQL Server forensics

TORONTO -- The Web was originally designed for housing public content, but the fact that it’s now used to build applications housing private data make it a ripe platform for malicious attacks, according to one speaker at the SecTor 2007 conference in Toronto this week.

“The Web is where the wild things are nowadays,” said Dan Kaminsky, director of penetration testing at Seattle-based security consultancy IOActive, during a session on Domain Name Server (DNS) rebinding attacks.

More in CIO Canada

DNS servers open to attack

Essentially, DNS translates human-readable computer hostnames into IP addresses. The DNS rebinding attacks subvert the DNS same-origin policy that assumes information stemming from the same origin must be trusted identically, said Kaminsky, but the reality is, the translations during this process can change at any time.

DNS rebinding attacks take advantage of this fundamental Web design flaw, breaking the Internet’s security policy and converting browsers into open network proxies, said Kaminsky, adding that this ultimately exposes every corporate network. “Corporate firewalls are bypassed via lured browsers.”

One of the contributing issues is people tend to use DNS TTL (Time to Live) – which defines how long records should live before getting discarded – as a security technology, he said, when in fact overriding the TTL can be “quite trivial”.

Considering that in DNS, multiple IP addresses can be transmitted besides the genuine one, it’s possible to create a VPN (virtual private network) into a corporation, said Kaminsky.

Kaminsky acknowledged the challenge facing organizations given the wide variety of DNS rebinding mechanisms out there, but he did share some suggestions that might help corporations, including configuring corporate servers to not transmit valuable information back to unrecognizable host systems.

Also, he said, it’s useful to perform external to internal routing checks to stop sites on the Internet from routing to internal targets on the corporate Intranet.

Also at SecTor 2007, challenges around corporate database attacks and methods to perform forensic investigation on SQL Server 2005 systems to determine possible data breaches were discussed.

The database has become a critical asset to organizations because of the critical information it holds, like financial, healthcare and human resources data, said Kevvie Fowler, manager of managed security services at Longueil, Quebec-based healthcare and financial technology provider Emergis Inc. “All this critical stuff that organizations need to share, maintain, process.”

Besides that, there is an industry trend toward scaling down to fewer consolidated systems, given the high cost of maintenance of databases, said Fowler.


Sign up for our Newsletters












Print |  Views: 1557   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Kathleen Lau Kathleen Lau was a senior writer with ITWorldCanada.com and ComputerWorld Canada from December 2006 to August 2011.In her role as senior writer, she covered broadly technology news and issues r... more

Related Content

SevOne updates network performance management appliance
SevOne updates network performance management applianceCompany about to move into Canada with Linux-powered device that offers real-time polling of network devices
Strategies for scaling and securing VoIP
Strategies for scaling and securing VoIPVoIP vendors say they deliver scalability and security. And InteropLabs testing mostly proved them right in multivendor settings. But testing also revealed some implementation glitches in both of those areas, and pinpointed a few missing pieces when it comes to key exchange for securing VoIP traffic.
RSA: Attendees fail on security
RSA: Attendees fail on security More than half of the wireless LAN devices being used at this week’s RSA Conference on information security are themselves unsecured.
Are database admins keeping up with the database?
at ibm corp.’s information on demand conference earlier this week, i had a conversation about the future of databases with anant jhingran, the company’s vice-president and chief technology officer for information management.  
Honey I shrunk the threats!
 by joaquim p. menezes - it’s called “honeyjax” and no, it isn’t another donut brand. it’
Secure in Anne's World
flashback to a new york city trip a couple years ago. i was passing through u.s. immigration at pearson, and getting a look from the border guard that could only be described as "askance." (if you've ever gotten that look from an ins official, you'll know what i mean.) my paperwork came back to me in a big red clipboard, which, i soon discovered, is not good.i was ushered off to a small

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.