Apple has failed to fully patch a DNS vulnerability, say researchers

Apple misses mark on DNS patch

Leopard remains vulnerable to cache poisoning, say researchers

Written by Shaun Nichols in San Francisco

Security researchers are claiming that Apple has failed to fully patch the high profile DNS cache poisoning error.

The company issued the patch last week as part of a larger security update. The so-called Kaminsky flaw (named after its discoverer, Dan Kaminsky) has sent vendors scrambling to patch what is said to be a fundamental vulnerability in the DNS system.

Advertisement

According to Andrew Storms, director of security operations for network security firm nCircle, Apple's patch doesn't quite do the job. Storms found that the update doesn't force source port randomisation for client libraries, an essential fix for preventing the spooking attack.

Storms said that while the server component of the error is fixed, client machines remain vulnerable.

"For Apple, it matters most that they patch the client libraries since there are so few OSX recursive servers in use," he noted.

"The bottom line is that despite this update, it appears that the client libraries still aren't patched."

Storms was not the only person to note Apple's oversight. Sans researcher Swa Frantzen also noticed the flaw. Frantzen pointed out that a fully patched Leopard system still uses incrementing ports, making port selection predictable and allowing an attacker to still perform the cache-poisoning exploit.

"So Apple might have fixed some of the more important parts for servers, but is far from done yet as all the clients linked against a DNS client library still need to get the workaround for the protocol weakness," said Frantzen.

Comments

White papers

Related jobs

More Accounting jobs

Spotlight

Stuart Bridges, Hiscox

Stuart Bridges: FD of Hiscox

Dull is the new black in these straightened times –...

Top 30 Accounting Networks and Associations 2008

The race to become the biggest firm on the planet...

Barack Obama Accountancy Age cover October 2008

Obama: asset or liability?

What an Obama presidency could mean for you

Find your next job

Find your next job
Salary Checker

Job of the week

More finance jobs

Newsletters

Sign up here for the very latest news delivered to your inbox. Choose from the following options:

Your next job

Have your say

Will proposed tax cuts help to stimulate the economy?
Yes
No

Advertisement

Search white papers

Search white papers

Advertisement