On GameSpot: The biggest video game news of 2009
BNET Business Network:
BNET
TechRepublic
ZDNet

By Tom Espiner ZDNet UK
Posted on ZDNet News: Jul 29, 2009 12:54:55 PM

An exploit that a hacker could use to crash internet servers is being used in the wild.

The exploit targets a vulnerability in Bind 9, the most widely used DNS server standard, warned the Internet Systems Consortium (ISC) on Tuesday. ISC is the organization that supports Bind.

The hole in Bind 9 has no workaround. Administrators must upgrade to Bind versions 9.4.3-P3, 9.5.1-P3 or 9.6.1-P1 to mitigate the threat. The exploit, which a hacker could use to launch an attack against unpatched master servers, is easily available, warned ISC.

"An active remote exploit is in wide circulation at this time," said ISC in an advisory.

The Berkeley Internet Name Domain (Bind) is the most widely used DNS server standard. Bind 9 was coded to overcome security issues associated with Bind, and supports DNS Security Extensions, (DNSSEC), or encrypted DNS.

The Bind 9 dynamic update DOS vulnerability affects master servers for one or more zones. Receipt of a specially crafted dynamic update message may cause Bind 9 master servers to crash, said ISC.

This article was originally posted on ZDNet UK.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 9 Talkback(s)
wow, if everyone...
was as stupid and ignorant as you, we would have no world left. try looking at windows instead. how many security holes are there?? i will bet you that there will be over 500 new vulnerabilities found... (Read the rest)
Posted by: crabbypup Posted on: 08/02/09 You are currently: a Guest | | Terms of Use
When will we learn to stop using Windows?  NonZealot | 07/29/09
I place the blame squarely on linux  Loverock Davidson | 07/29/09
Yay, the Help Desk guy speaks!  B.O.F.H. | 07/29/09
You tell me  Loverock Davidson | 07/29/09
bind isn't installed by default  robertjtownley@... | 07/29/09
wow, if everyone...  crabbypup | 08/02/09
smart people doing smart things  ThinkFairer | 07/29/09
RE: High-risk internet server exploit goes wild  jameslynesophos | 07/30/09
RE: High-risk internet server exploit goes wild  bob@... | 07/31/09

What do you think?

SmartPlanet

Click Here