FEATURED VIDEO
Sponsored By:
SLIDE SHOWS
As if they needed more stress, organizations are facing evolving and increasingly stringent compliance regulations from the Payment Card Industry, as well as Sarbanes-Oxley, HIPAA and others. Here are a few security compliance products that can make the audit process less excruciating.
Here are 10 of the distributor's hottest new offerings winning over solution providers.
New smartphones from Sony, Motorola and the first-ever Twitter-only mobile device -- the TwitterPeek -- headline a busy week for handset makers as the holiday shopping season heats up.
INSIDE CHANNELWEB

Apple Finally Issues Fix For Critical DNS Security Flaw


By Jennifer Hagendorf Follett, ChannelWeb

10:58 AM EDT Fri. Aug. 01, 2008
Apple has finally issued an update that fixes a security hole opened by the critical Domain Name System (DNS) flaw disclosed earlier this month.

The Cupertino, Calif.-based computer company Friday posted Security Update 2008-005, a fix that plugs several security holes, including Apple's implementation of the BIND (Berkeley Internet Name Domain) server, which left users of its Mac OS X operating system susceptible to the DNS flaw.

The DNS problem was discovered by security researcher Dan Kaminsky, who planned to disclose the threat at next week's Black Hat USA 2008 in Las Vegas. But two researchers leaked details of the flaw and how to exploit it in separate blog posts last week, exposing equipment from numerous vendors to security risks.

While vendors such as Cisco Systems and Microsoft were quick to issue fixes, Apple came under fire for moving too slowly to patch up the hole.

The DNS error stems from a fundamental flaw in the DNS protocol, a function which provides a back and forth translation of host URLs to IP addresses. The vulnerability could be exploited by attackers to launch cache poisoning attacks by creating fake messages accepted by the DNS that can trick the server into delivering an incorrect request. Attackers could then use the flaw to redirect Internet traffic to malicious Web sites and install arbitrary code on users PCs.

Apple's security update addresses the DNS exploit as well as several other fixes that impact Mac OS X Server 10.4, Mac OS X 10.4.11, Mac OS X Server 10.5 and Mac OS X 10.5.4

--Stefanie Hoffman contributed to this story.

 
Channelweb : Promofinder
FEATURED PROMOTIONS
HES/HWS 30% End User Discount
HES/HWS 30% End User Discount
DLP Monitor 20% End User Discount
DLP Monitor 20% End User Discount
RELATED BLOG >>
Photo
SpamTitan offers comprehensive e-mail security, protecting against phishing attacks, viruses, malware and, yes, spam too.
ADVERTISEMENT




CHANNEL SERVICES >>

techcareers logo Search Jobs:


  

Post Resume|Employers

Recent Post:


Network Engineer
Lawrence Berkeley National Lab seeking Network Engineer in Berkeley, CA
spacer