Expert: SOA vulnerable to DNS security flaw, too
At the Black Hat security confab currently taking place in Las Vegas Dan Kaminsky disclosed his findings around the Domain Name Server flaw. Tim Wilson of Dark Reading reported on Kaminsky's presentation. The flaw enables attackers to "exploit the DNS design to quickly guess the transaction ID of an address query and potentially re-route the user to an unexpected domain." Kaminsky noted the DNS flaw can affect any system that uses the Internet, including older applications such as FTP. "Back-end IT systems such as Telnet, SNMP, authentication servers (such as Radius), backup and restoral systems, and even service-oriented architecture (SOA) environments all use DNS, and could be subject to attack via the newly discovered flaw."
read more »
Bury