Email this article   Print article 


Apple DNS Security Patch Flawed, Leaves Users At Risk

By Jennifer Hagendorf Follett
August 02, 2008    1:10 AM ET

Apple finally rolled out a software update to fix the much-heralded Domain Name System (DNS) security flaw, but it seems the celebration may have been premature.

The Cupertino, Calif.-based vendor rolled out Security Update 2008-005, a fix that Apple said plugs several security holes, including its implementation of the BIND (Berkeley Internet Name Domain) server, which left users of its Mac OS X operating system susceptible to the DNS flaw disclosed earlier this month.

However, several security researchers Friday said Apple's DNS patch doesn't actually fix the problem and that Mac users are still at risk.

"Did Apple forget to patch something? By the look of things, the DNS client on the OSX 10.4.11 distribution still has not been patched," said security researcher Andrew Storms, director of security operations at Ncircle Network Security, in a blog post.

Apple's update was supposed to introduce port randomization to help block cache poisoning attacks, a threat exposed by the DNS flaw. But even after installing the patch, Storms said his system still was not randomizing the source port.

"The bottom line is that despite this update, it appears that the client libraries still aren't patched," Storms said.

Another security researcher, Swa Frantzen of the SANS Institute found the same problem with Apple's software patch.

"So Apple might have fixed some of the more important parts for servers, but is far from done yet as all the clients linked against a DNS client library still need to get the workaround for the protocol weakness," Frantzen said in a blog post.

The DNS problem was discovered by security researcher Dan Kaminsky, who planned to disclose the threat at next week's Black Hat USA 2008 in Las Vegas. But two researchers last week leaked details of the flaw and how to exploit it, leaving equipment from several vendors open to attack.

Several vendors moved immediately to issue patches that addressed the flaw, but Apple held back, drawing criticism for its slow response.

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

Head-To-Head: Symantec Vs. McAfee In Endpoint Protection

McAfee and Symantec are archrivals with a firm grip on the North American security market. CRN pits both vendors' endpoint security products against each other and names a winner.

The 8 Steps Behind The Massive $45M Cyber Bank Heist

More than $45 million was stolen from banks in the U.S. and 19 other countries in a scheme that law enforcement is calling an international conspiracy to drain millions from bank accounts using stolen debit cards and PIN numbers. Here's how they did it.

Name Of The Game: Top 10 States For Identity Theft

A Federal Trade Commission report provides statistics on identity theft and fraud complaints in 2012. Learn which state has the dubious distinction of having the most victims.

  More Slide Shows




Related Videos
Loading...