Apple finally fixes DNS bug

posted Sep 15th 2008 2:24pm by Eliot Phillips
filed under: iphone hacks, macs hacks, news, security hacks

With today’s release of Security Update 2008-006 Apple has finally addressed this summer’s DNS bug. In their previous update they fixed BIND, but that only affects people running servers. Now, they’ve updated mDNSResponder. Clients are no longer susceptible to DNS cache poisoning attacks thanks to the inclusion of source port randomization.

The Security Update addresses some other interesting bugs. Time Machine was saving sensitive logs without using the proper permissions, so any user could view them.

[photo: edans]

Black Hat 2008: Dan Kaminsky releases DNS information

posted Aug 6th 2008 5:00pm by fabienneserriere
filed under: cons, misc hacks, news


[Dan Kaminsky]’s much anticipated talk on his DNS findings finally happened at Black Hat 2008 in Las Vegas today. [Dan] has already uploaded the complete slides from his talk as well as posted a short summary to his site. New information in the slides since our previous coverage includes “Forgot My Password” attacks and new attacks on internal network vulnerabilities as a side of effect of DNS cache poisoning. [Dan]’s talk today was over capacity; our shot of the conference room overflow is shown above.




Hack a Day serves up fresh hacks each day, every day from around the web and a special How-To hack each week.

Send us your hacks