<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="http://feedproxy.google.com/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feedproxy.google.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" xml:lang="en" xml:base="http://www.dnsfool.com/wp-atom.php">
	<title type="text">DNS Fool</title>
	<subtitle type="text">News about the Domain Name System</subtitle>

	<updated>2008-12-22T16:31:18Z</updated>
	<generator uri="http://wordpress.org/" version="2.7">WordPress</generator>

	<link rel="alternate" type="text/html" href="http://www.dnsfool.com" />
	<id>http://www.dnsfool.com/feed/atom/</id>
	

			<link rel="self" href="http://feedproxy.google.com/DnsFool" type="application/atom+xml" /><entry>
		<author>
			<name>Cory Wright</name>
						<uri>http://www.dnsfool.com/</uri>
					</author>
		<title type="html"><![CDATA[DNSSEC Deployment Moves Forward, Slightly]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DnsFool/~3/M17yFDj3pb8/" />
		<id>http://www.dnsfool.com/?p=51</id>
		<updated>2008-12-22T16:31:18Z</updated>
		<published>2008-12-22T15:13:39Z</published>
		<category scheme="http://www.dnsfool.com" term="Security" /><category scheme="http://www.dnsfool.com" term="DNSSEC" />		<summary type="html"><![CDATA[Although DNSSEC has been in the works for over a decade now, until recently there has been little motivation to begin working on a widescale deployment. Of course, after Dan Kaminsky&#8217;s announcement this past summer there is now a scramble to increase the security of the domain name system.
Earlier this year the U.S. Government issued [...]]]></summary>
		<content type="html" xml:base="http://www.dnsfool.com/2008/12/22/dnssec-deployment-moves-forward-slightly/">&lt;p&gt;Although &lt;a href="http://en.wikipedia.org/wiki/DNSSEC"&gt;DNSSEC&lt;/a&gt; has been in the works for over a decade now, until recently there has been little motivation to begin working on a widescale deployment. Of course, after Dan Kaminsky&amp;#8217;s &lt;a href="http://www.wired.com/techbiz/people/magazine/16-12/ff_kaminsky"&gt;announcement&lt;/a&gt; this past summer there is now a scramble to increase the security of the domain name system.&lt;/p&gt;
&lt;p&gt;Earlier this year the U.S. Government &lt;a href="http://www.dnsfool.com/2008/08/27/us-government-mandates-dnssec/"&gt;issued an order&lt;/a&gt; for the .gov domain to be signed by January 2009.  Furthermore, all subdomains of .gov are required to be compliant by December 2009.  According to IETF participants the first goal has been met, and the .gov domain is already signed ahead of the deadline.  There are also immediate plans to sign the .mil domains used by the U.S. Military.&lt;/p&gt;
&lt;p&gt;The directive by the U.S. Government was the first major push for DNSSEC deployment and it has spurred action by other big players in the DNS world.  Recently several major DNS vendors announced they had formed the &lt;a href="http://dnsseccoalition.org/"&gt;DNSSEC Industry Coalition&lt;/a&gt; to help facilitate DNSSEC deployment.  The member venders are &lt;a href="http://www.verisign.com"&gt;VeriSign&lt;/a&gt;, &lt;a href="http://www.pir.org/"&gt;The Public Internet Registry&lt;/a&gt;, &lt;a href="http://www.nominet.org.uk/"&gt;Nominet UK&lt;/a&gt;, &lt;a href="http://www.afilias.info/"&gt;Afilias&lt;/a&gt;, &lt;a href="http://www.neustar.biz/"&gt;NeuStar&lt;/a&gt;, &lt;a href="http://www.iis.se/"&gt;The Foundation for Internet Infrastructure&lt;/a&gt;, and &lt;a href="http://www.educause.edu"&gt;Educause&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In October the U.S. &lt;a rel="external" href="http://www.ntia.doc.gov/" target="_blank"&gt;National Telecommunications and Information Agency&lt;/a&gt; (NTIA) &lt;a href="http://www.heise.de/english/newsticker/news/119336"&gt;issued&lt;/a&gt; a Notice of Inquiry asking for feedback regarding the deployment of DNSSEC.  The &lt;a href="http://www.ntia.doc.gov/DNS/DNSSEC.html"&gt;responses&lt;/a&gt; were overwhelmingly in favor of a quick and widespread DNSSEC deployment, which is not surprising considering a large number of the respondants represent organizations who stand to profit from such a rushed deployment.&lt;/p&gt;
&lt;p&gt;However, not everyone is convinced that DNSSEC is the best solution at this time. Until the root servers are signed there is no way to authenticate the DNS session and verify the integrity of the entire response.  This is part of the reason that the &lt;a href="http://www.networkworld.com/news/2008/112008-ietf-dns-debate.html"&gt;IETF has yet to decide&lt;/a&gt; on an immediate solution to the problems raised by the bug Kaminsky found.  Paul Hoffman &lt;a href="http://www.ntia.doc.gov/dns/comments/comment012.pdf"&gt;put it simply&lt;/a&gt; (PDF):&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;&amp;#8220;Let&amp;#8217;s say the root is signed tomorrow. Let&amp;#8217;s say all the important top-level domains are signed. It&amp;#8217;s still    no good unless all of the domains are signed. You can&amp;#8217;t just deploy DNSSEC. You have to deploy it universally.&amp;#8221;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;This is the heart of the &amp;#8220;chicken and egg&amp;#8221; problem that DNSSEC advocates have struggled to fight for years.  Until it is deployed everywhere, DNSSEC isn&amp;#8217;t really 100% effective.  And no one wants to deploy a solution that isn&amp;#8217;t 100% effective, especially when it comes to an issue of security.  As of December 20, 2008, DNSSEC has yet to be deployed to even &lt;a href="http://secspider.cs.ucla.edu/"&gt;15,000 domains&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;No matter what route the Internet community decides to take to secure the DNS, we still have a very long road ahead of us.&lt;/p&gt;

&lt;span class="slashdigglicious"&gt;
&lt;a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F12%2F22%2Fdnssec-deployment-moves-forward-slightly%2F&amp;amp;title=DNSSEC+Deployment+Moves+Forward%2C+Slightly" title="Slashdot It!"&gt;&lt;img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /&gt;&lt;/a&gt;
&lt;a href="http://digg.com/submit?phase=2&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F12%2F22%2Fdnssec-deployment-moves-forward-slightly%2F&amp;amp;title=DNSSEC+Deployment+Moves+Forward%2C+Slightly" title="Digg This Story"&gt;&lt;img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /&gt;&lt;/a&gt;
&lt;a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F12%2F22%2Fdnssec-deployment-moves-forward-slightly%2F&amp;amp;title=DNSSEC+Deployment+Moves+Forward%2C+Slightly" title="Reddit"&gt;&lt;img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /&gt;&lt;/a&gt;
&lt;a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F12%2F22%2Fdnssec-deployment-moves-forward-slightly%2F&amp;amp;title=DNSSEC+Deployment+Moves+Forward%2C+Slightly" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;amp;noui&amp;amp;jump=close&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F12%2F22%2Fdnssec-deployment-moves-forward-slightly%2F&amp;amp;title=DNSSEC+Deployment+Moves+Forward%2C+Slightly', 'delicious', 'toolbar=no,width=700,height=400'); return false;"&gt;&lt;img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /&gt;&lt;/a&gt;
&lt;a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F12%2F22%2Fdnssec-deployment-moves-forward-slightly%2F" title="Share on Facebook"&gt;&lt;img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /&gt;&lt;/a&gt;
&lt;a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F12%2F22%2Fdnssec-deployment-moves-forward-slightly%2F" title="Add to my Technorati Favorites"&gt;&lt;img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /&gt;&lt;/a&gt;
&lt;a href="http://www.google.com/bookmarks/mark?op=edit&amp;amp;output=popup&amp;amp;bkmk=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F12%2F22%2Fdnssec-deployment-moves-forward-slightly%2F&amp;amp;title=DNSSEC+Deployment+Moves+Forward%2C+Slightly" title="Save to Google Bookmarks"&gt;&lt;img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /&gt;&lt;/a&gt;
&lt;a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F12%2F22%2Fdnssec-deployment-moves-forward-slightly%2F&amp;amp;title=DNSSEC+Deployment+Moves+Forward%2C+Slightly" title="Stumble it!"&gt;&lt;img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /&gt;&lt;/a&gt;
&lt;/span&gt;&lt;img src="http://feedproxy.google.com/~r/DnsFool/~4/M17yFDj3pb8" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://www.dnsfool.com/2008/12/22/dnssec-deployment-moves-forward-slightly/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.dnsfool.com/2008/12/22/dnssec-deployment-moves-forward-slightly/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<feedburner:origLink>http://www.dnsfool.com/2008/12/22/dnssec-deployment-moves-forward-slightly/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Cory Wright</name>
						<uri>http://www.dnsfool.com/</uri>
					</author>
		<title type="html"><![CDATA[U.S. Government Mandates DNSSEC]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DnsFool/~3/trEWlOUjgi8/" />
		<id>http://www.dnsfool.com/?p=44</id>
		<updated>2008-08-27T23:18:04Z</updated>
		<published>2008-08-27T17:44:34Z</published>
		<category scheme="http://www.dnsfool.com" term="Root Servers" /><category scheme="http://www.dnsfool.com" term="Security" /><category scheme="http://www.dnsfool.com" term="DNSSEC" /><category scheme="http://www.dnsfool.com" term="US Government" /><category scheme="http://www.dnsfool.com" term="zone enumeration" />		<summary type="html"><![CDATA[In response to claims of &#8220;foot-dragging&#8221; with regards to DNS security, the United States government has ordered the administrators of all .gov domains to implement DNSSEC before January 2009.
DNSSEC is a somewhat controversial set of extensions to the DNS protocol designed to provide protection from forged data.  Although it was first proposed in 1995, DNSSEC [...]]]></summary>
		<content type="html" xml:base="http://www.dnsfool.com/2008/08/27/us-government-mandates-dnssec/">&lt;p&gt;In response to claims of &amp;#8220;&lt;a href="http://blog.wired.com/27bstroke6/2008/08/experts-accuse.html"&gt;foot-dragging&lt;/a&gt;&amp;#8221; with regards to DNS security, the United States government has &lt;a href="http://www.gcn.com/online/vol1_no1/46987-1.html"&gt;ordered&lt;/a&gt; the administrators of all .gov domains to implement DNSSEC before January 2009.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://en.wikipedia.org/wiki/DNSSEC"&gt;DNSSEC&lt;/a&gt; is a somewhat controversial set of extensions to the DNS protocol designed to provide protection from forged data.  Although it was first proposed in 1995, DNSSEC has not been widely adopted and as of a few weeks ago only &lt;a href="http://marc.info/?l=djbdns&amp;amp;m=121832806123954"&gt;99 .com domains&lt;/a&gt; were using it (here&amp;#8217;s a &lt;a href="http://www.xelerance.com/dnssec/"&gt;map&lt;/a&gt; of worldwide deployments).  Of the many concerns preventing deployment, the two most controversial have been &amp;#8220;zone enumeration&amp;#8221; and the issue of who controls the master keys.&lt;/p&gt;
&lt;p&gt;The matter of key ownership was raised again last year when the U.S. Department of Homeland Security &lt;a href="http://www.heise.de/english/newsticker/news/87655"&gt;announced&lt;/a&gt; that it wanted to manage the root keys.  Operators of many other top level domains took issue with this, and proposed that &lt;a href="http://www.icann.org/"&gt;ICANN&lt;/a&gt;/&lt;a href="http://www.iana.org/"&gt;IANA&lt;/a&gt; be tasked with root key management.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Update:&lt;/strong&gt; A &lt;a href="http://www.whitehouse.gov/omb/memoranda/fy2008/m08-23.pdf"&gt;PDF of the mandate&lt;/a&gt; is available from the Whitehouse website.&lt;/p&gt;

&lt;span class="slashdigglicious"&gt;
&lt;a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F27%2Fus-government-mandates-dnssec%2F&amp;amp;title=U.S.+Government+Mandates+DNSSEC" title="Slashdot It!"&gt;&lt;img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /&gt;&lt;/a&gt;
&lt;a href="http://digg.com/submit?phase=2&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F27%2Fus-government-mandates-dnssec%2F&amp;amp;title=U.S.+Government+Mandates+DNSSEC" title="Digg This Story"&gt;&lt;img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /&gt;&lt;/a&gt;
&lt;a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F27%2Fus-government-mandates-dnssec%2F&amp;amp;title=U.S.+Government+Mandates+DNSSEC" title="Reddit"&gt;&lt;img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /&gt;&lt;/a&gt;
&lt;a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F27%2Fus-government-mandates-dnssec%2F&amp;amp;title=U.S.+Government+Mandates+DNSSEC" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;amp;noui&amp;amp;jump=close&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F27%2Fus-government-mandates-dnssec%2F&amp;amp;title=U.S.+Government+Mandates+DNSSEC', 'delicious', 'toolbar=no,width=700,height=400'); return false;"&gt;&lt;img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /&gt;&lt;/a&gt;
&lt;a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F27%2Fus-government-mandates-dnssec%2F" title="Share on Facebook"&gt;&lt;img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /&gt;&lt;/a&gt;
&lt;a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F27%2Fus-government-mandates-dnssec%2F" title="Add to my Technorati Favorites"&gt;&lt;img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /&gt;&lt;/a&gt;
&lt;a href="http://www.google.com/bookmarks/mark?op=edit&amp;amp;output=popup&amp;amp;bkmk=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F27%2Fus-government-mandates-dnssec%2F&amp;amp;title=U.S.+Government+Mandates+DNSSEC" title="Save to Google Bookmarks"&gt;&lt;img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /&gt;&lt;/a&gt;
&lt;a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F27%2Fus-government-mandates-dnssec%2F&amp;amp;title=U.S.+Government+Mandates+DNSSEC" title="Stumble it!"&gt;&lt;img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /&gt;&lt;/a&gt;
&lt;/span&gt;&lt;img src="http://feedproxy.google.com/~r/DnsFool/~4/trEWlOUjgi8" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://www.dnsfool.com/2008/08/27/us-government-mandates-dnssec/#comments" thr:count="2" />
		<link rel="replies" type="application/atom+xml" href="http://www.dnsfool.com/2008/08/27/us-government-mandates-dnssec/feed/atom/" thr:count="2" />
		<thr:total>2</thr:total>
	<feedburner:origLink>http://www.dnsfool.com/2008/08/27/us-government-mandates-dnssec/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Cory Wright</name>
						<uri>http://www.dnsfool.com/</uri>
					</author>
		<title type="html"><![CDATA[Looking Back on Kaminsky&#8217;s DNS Bug]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DnsFool/~3/u1DFPdQwbc0/" />
		<id>http://www.dnsfool.com/?p=36</id>
		<updated>2008-08-18T17:14:17Z</updated>
		<published>2008-08-18T16:53:41Z</published>
		<category scheme="http://www.dnsfool.com" term="Articles" /><category scheme="http://www.dnsfool.com" term="Security" /><category scheme="http://www.dnsfool.com" term="Dan Kaminsky" /><category scheme="http://www.dnsfool.com" term="Linux Journal" /><category scheme="http://www.dnsfool.com" term="New York Times" />		<summary type="html"><![CDATA[A lot has happened in the world of DNS since July 8th.  Of course, that is when Dan Kaminsky revealed his now famous DNS bug and the patching panic began.  Since that time there have been many explanations of the bug, along with much discussion about also how the bug can be exploited and why [...]]]></summary>
		<content type="html" xml:base="http://www.dnsfool.com/2008/08/18/looking-back-kaminskys-dns-bug/">&lt;p&gt;A lot has happened in the world of DNS since July 8th.  Of course, that is when Dan Kaminsky revealed his now famous DNS bug and the patching panic began.  Since that time there have been many explanations of the bug, along with much discussion about also how the bug can be exploited and why it is a big deal.  I&amp;#8217;ve contributed to this discussion in the form of two articles posted on &lt;a href="http://www.linuxjournal.com/"&gt;LinuxJournal.com&lt;/a&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.linuxjournal.com/content/understanding-kaminskys-dns-bug"&gt;Understanding Kaminsky&amp;#8217;s DNS Bug&lt;/a&gt; - An overview of how the bug can be exploited.&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.linuxjournal.com/content/dns-bug-why-you-should-care"&gt;The DNS Bug: Why You Should Care&lt;/a&gt; - A look at the importance of this bug to everyone on the Internet.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;It isn&amp;#8217;t often that the New York Times covers topics like the Domain Name System, but this security issue was enough to warrant &lt;a href="http://www.nytimes.com/2008/07/30/technology/30flaw.html"&gt;two&lt;/a&gt; &lt;a href="http://www.nytimes.com/2008/08/09/technology/09flaw.html"&gt;articles&lt;/a&gt; on the award winning news site.&lt;/p&gt;
&lt;p&gt;It&amp;#8217;s been said many times by many people, but it really is amazing that this bug went undiscovered for 25 years.  Once it is explained it just seems so simple.  How could we not have seen it?&lt;/p&gt;
&lt;p&gt;But how do we know that someone else didn&amp;#8217;t discover this bug long ago?  For all we know, a bad guy may have been exploiting this issue for years, undetected.  This is why it is so important that the Internet community embrace full-disclosure security practices.  Information exists, and it&amp;#8217;s better for it to be available to everyone, publicly, than to just the bad guys, privately.&lt;/p&gt;
&lt;p&gt;Even if the bug had not been known before, and Dan didn&amp;#8217;t accidentally find it, how do we know a bad guy wasn&amp;#8217;t on the brink of discovering it?  How would the news media have reacted to the story in that case?&lt;/p&gt;
&lt;p&gt;Let&amp;#8217;s just be glad Dan Kaminsky is on our side.  &lt;img src='http://www.dnsfool.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /&gt; &lt;/p&gt;

&lt;span class="slashdigglicious"&gt;
&lt;a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F18%2Flooking-back-kaminskys-dns-bug%2F&amp;amp;title=Looking+Back+on+Kaminsky%26%238217%3Bs+DNS+Bug" title="Slashdot It!"&gt;&lt;img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /&gt;&lt;/a&gt;
&lt;a href="http://digg.com/submit?phase=2&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F18%2Flooking-back-kaminskys-dns-bug%2F&amp;amp;title=Looking+Back+on+Kaminsky%26%238217%3Bs+DNS+Bug" title="Digg This Story"&gt;&lt;img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /&gt;&lt;/a&gt;
&lt;a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F18%2Flooking-back-kaminskys-dns-bug%2F&amp;amp;title=Looking+Back+on+Kaminsky%26%238217%3Bs+DNS+Bug" title="Reddit"&gt;&lt;img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /&gt;&lt;/a&gt;
&lt;a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F18%2Flooking-back-kaminskys-dns-bug%2F&amp;amp;title=Looking+Back+on+Kaminsky%26%238217%3Bs+DNS+Bug" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;amp;noui&amp;amp;jump=close&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F18%2Flooking-back-kaminskys-dns-bug%2F&amp;amp;title=Looking+Back+on+Kaminsky%26%238217%3Bs+DNS+Bug', 'delicious', 'toolbar=no,width=700,height=400'); return false;"&gt;&lt;img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /&gt;&lt;/a&gt;
&lt;a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F18%2Flooking-back-kaminskys-dns-bug%2F" title="Share on Facebook"&gt;&lt;img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /&gt;&lt;/a&gt;
&lt;a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F18%2Flooking-back-kaminskys-dns-bug%2F" title="Add to my Technorati Favorites"&gt;&lt;img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /&gt;&lt;/a&gt;
&lt;a href="http://www.google.com/bookmarks/mark?op=edit&amp;amp;output=popup&amp;amp;bkmk=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F18%2Flooking-back-kaminskys-dns-bug%2F&amp;amp;title=Looking+Back+on+Kaminsky%26%238217%3Bs+DNS+Bug" title="Save to Google Bookmarks"&gt;&lt;img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /&gt;&lt;/a&gt;
&lt;a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F18%2Flooking-back-kaminskys-dns-bug%2F&amp;amp;title=Looking+Back+on+Kaminsky%26%238217%3Bs+DNS+Bug" title="Stumble it!"&gt;&lt;img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /&gt;&lt;/a&gt;
&lt;/span&gt;&lt;img src="http://feedproxy.google.com/~r/DnsFool/~4/u1DFPdQwbc0" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://www.dnsfool.com/2008/08/18/looking-back-kaminskys-dns-bug/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.dnsfool.com/2008/08/18/looking-back-kaminskys-dns-bug/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<feedburner:origLink>http://www.dnsfool.com/2008/08/18/looking-back-kaminskys-dns-bug/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Cory Wright</name>
						<uri>http://www.dnsfool.com/</uri>
					</author>
		<title type="html"><![CDATA[BIND Addresses Performance and Stability Issues]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DnsFool/~3/xe1_YoH5cIQ/" />
		<id>http://www.dnsfool.com/?p=35</id>
		<updated>2008-08-02T14:43:27Z</updated>
		<published>2008-08-02T14:43:27Z</published>
		<category scheme="http://www.dnsfool.com" term="BIND" /><category scheme="http://www.dnsfool.com" term="Security" /><category scheme="http://www.dnsfool.com" term="patches" /><category scheme="http://www.dnsfool.com" term="Windows" />		<summary type="html"><![CDATA[The initial patches provided for better port randomization in BIND caused it to experience performance issues.  Today ISC has provided a second patch for each of the Unix versions of 9.3.5, 9.4.2, and 9.5.0 that addresses the problems introduced in the first patch.  As stated in the release notes, this update provides:

performance improvement over the [...]]]></summary>
		<content type="html" xml:base="http://www.dnsfool.com/2008/08/02/bind-addresses-performance-and-stability-issues/">&lt;p&gt;The initial patches provided for better port randomization in BIND caused it to experience &lt;a href="http://www.dnsfool.com/2008/07/30/bind-issues-on-high-traffic-caches/"&gt;performance issues&lt;/a&gt;.  Today ISC has provided a second patch for each of the Unix versions of 9.3.5, 9.4.2, and 9.5.0 that addresses the problems introduced in the first patch.  As stated in the release notes, this update provides:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;performance improvement over the P1 releases, namely
&lt;ul&gt;
&lt;li&gt;significantly remedying the port allocation issues&lt;/li&gt;
&lt;li&gt;allowing TCP queries and zone transfers while issuing as many&lt;br /&gt;
outstanding UDP queries as possible&lt;/li&gt;
&lt;li&gt;additional security of port randomization at the same level as P1&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additionally, the patch for 9.5.0 includes &amp;#8220;fixes for several bugs in the 9.5.0 base code.&amp;#8221;&lt;/p&gt;
&lt;p&gt;Those using BIND for Windows will need to wait a little longer for the performance fixes as these patches do not fix the issues on that platform.&lt;/p&gt;
&lt;p&gt;The updated versions can be downloaded directly from the &lt;a href="http://www.isc.org/sw/bind/"&gt;BIND page&lt;/a&gt; on the ISC website.&lt;/p&gt;

&lt;span class="slashdigglicious"&gt;
&lt;a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F02%2Fbind-addresses-performance-and-stability-issues%2F&amp;amp;title=BIND+Addresses+Performance+and+Stability+Issues" title="Slashdot It!"&gt;&lt;img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /&gt;&lt;/a&gt;
&lt;a href="http://digg.com/submit?phase=2&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F02%2Fbind-addresses-performance-and-stability-issues%2F&amp;amp;title=BIND+Addresses+Performance+and+Stability+Issues" title="Digg This Story"&gt;&lt;img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /&gt;&lt;/a&gt;
&lt;a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F02%2Fbind-addresses-performance-and-stability-issues%2F&amp;amp;title=BIND+Addresses+Performance+and+Stability+Issues" title="Reddit"&gt;&lt;img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /&gt;&lt;/a&gt;
&lt;a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F02%2Fbind-addresses-performance-and-stability-issues%2F&amp;amp;title=BIND+Addresses+Performance+and+Stability+Issues" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;amp;noui&amp;amp;jump=close&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F02%2Fbind-addresses-performance-and-stability-issues%2F&amp;amp;title=BIND+Addresses+Performance+and+Stability+Issues', 'delicious', 'toolbar=no,width=700,height=400'); return false;"&gt;&lt;img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /&gt;&lt;/a&gt;
&lt;a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F02%2Fbind-addresses-performance-and-stability-issues%2F" title="Share on Facebook"&gt;&lt;img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /&gt;&lt;/a&gt;
&lt;a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F02%2Fbind-addresses-performance-and-stability-issues%2F" title="Add to my Technorati Favorites"&gt;&lt;img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /&gt;&lt;/a&gt;
&lt;a href="http://www.google.com/bookmarks/mark?op=edit&amp;amp;output=popup&amp;amp;bkmk=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F02%2Fbind-addresses-performance-and-stability-issues%2F&amp;amp;title=BIND+Addresses+Performance+and+Stability+Issues" title="Save to Google Bookmarks"&gt;&lt;img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /&gt;&lt;/a&gt;
&lt;a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F08%2F02%2Fbind-addresses-performance-and-stability-issues%2F&amp;amp;title=BIND+Addresses+Performance+and+Stability+Issues" title="Stumble it!"&gt;&lt;img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /&gt;&lt;/a&gt;
&lt;/span&gt;&lt;img src="http://feedproxy.google.com/~r/DnsFool/~4/xe1_YoH5cIQ" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://www.dnsfool.com/2008/08/02/bind-addresses-performance-and-stability-issues/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.dnsfool.com/2008/08/02/bind-addresses-performance-and-stability-issues/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<feedburner:origLink>http://www.dnsfool.com/2008/08/02/bind-addresses-performance-and-stability-issues/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Cory Wright</name>
						<uri>http://www.dnsfool.com/</uri>
					</author>
		<title type="html"><![CDATA[BIND Issues on High Traffic Caches]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DnsFool/~3/kexkQRRDKEI/" />
		<id>http://www.dnsfool.com/?p=34</id>
		<updated>2008-07-30T16:12:08Z</updated>
		<published>2008-07-30T16:12:08Z</published>
		<category scheme="http://www.dnsfool.com" term="BIND" /><category scheme="http://www.dnsfool.com" term="Apple" /><category scheme="http://www.dnsfool.com" term="bugs" /><category scheme="http://www.dnsfool.com" term="Security" />		<summary type="html"><![CDATA[ISC has issued a statement about the performance issues that many BIND administrators are seeing.
Evidently, the new security updates to BIND are causing problems in high traffic recursive environments (more than 10k queries/sec).  Specifically, the issue exists with BIND 9.5.0-P1.  Their statement recommends that systems affected by this be immediately downgraded to BIND 9.4.2-P1, which [...]]]></summary>
		<content type="html" xml:base="http://www.dnsfool.com/2008/07/30/bind-issues-on-high-traffic-caches/">&lt;p&gt;ISC has issued a &lt;a href="http://marc.info/?l=bind-users&amp;amp;m=121726908015389&amp;amp;w=2"&gt;statement&lt;/a&gt; about the performance issues that many BIND administrators are seeing.&lt;/p&gt;
&lt;p&gt;Evidently, the new security updates to BIND are causing problems in high traffic recursive environments (more than 10k queries/sec).  Specifically, the issue exists with BIND 9.5.0-P1.  Their statement recommends that systems affected by this be immediately downgraded to BIND 9.4.2-P1, which does not exhibit the problem.&lt;/p&gt;
&lt;p&gt;There is &lt;a href="http://news.cnet.com/8301-1009_3-10001811-83.html"&gt;speculation&lt;/a&gt; that this is the reason that Apple has delayed providing an update for Mac OS X Server.  It&amp;#8217;s been three weeks since the exploit was first announced and Apple has been noticably quiet among the companies publishing security updates.&lt;/p&gt;

&lt;span class="slashdigglicious"&gt;
&lt;a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F30%2Fbind-issues-on-high-traffic-caches%2F&amp;amp;title=BIND+Issues+on+High+Traffic+Caches" title="Slashdot It!"&gt;&lt;img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /&gt;&lt;/a&gt;
&lt;a href="http://digg.com/submit?phase=2&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F30%2Fbind-issues-on-high-traffic-caches%2F&amp;amp;title=BIND+Issues+on+High+Traffic+Caches" title="Digg This Story"&gt;&lt;img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /&gt;&lt;/a&gt;
&lt;a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F30%2Fbind-issues-on-high-traffic-caches%2F&amp;amp;title=BIND+Issues+on+High+Traffic+Caches" title="Reddit"&gt;&lt;img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /&gt;&lt;/a&gt;
&lt;a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F30%2Fbind-issues-on-high-traffic-caches%2F&amp;amp;title=BIND+Issues+on+High+Traffic+Caches" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;amp;noui&amp;amp;jump=close&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F30%2Fbind-issues-on-high-traffic-caches%2F&amp;amp;title=BIND+Issues+on+High+Traffic+Caches', 'delicious', 'toolbar=no,width=700,height=400'); return false;"&gt;&lt;img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /&gt;&lt;/a&gt;
&lt;a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F30%2Fbind-issues-on-high-traffic-caches%2F" title="Share on Facebook"&gt;&lt;img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /&gt;&lt;/a&gt;
&lt;a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F30%2Fbind-issues-on-high-traffic-caches%2F" title="Add to my Technorati Favorites"&gt;&lt;img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /&gt;&lt;/a&gt;
&lt;a href="http://www.google.com/bookmarks/mark?op=edit&amp;amp;output=popup&amp;amp;bkmk=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F30%2Fbind-issues-on-high-traffic-caches%2F&amp;amp;title=BIND+Issues+on+High+Traffic+Caches" title="Save to Google Bookmarks"&gt;&lt;img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /&gt;&lt;/a&gt;
&lt;a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F30%2Fbind-issues-on-high-traffic-caches%2F&amp;amp;title=BIND+Issues+on+High+Traffic+Caches" title="Stumble it!"&gt;&lt;img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /&gt;&lt;/a&gt;
&lt;/span&gt;&lt;img src="http://feedproxy.google.com/~r/DnsFool/~4/kexkQRRDKEI" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://www.dnsfool.com/2008/07/30/bind-issues-on-high-traffic-caches/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.dnsfool.com/2008/07/30/bind-issues-on-high-traffic-caches/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<feedburner:origLink>http://www.dnsfool.com/2008/07/30/bind-issues-on-high-traffic-caches/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Cory Wright</name>
						<uri>http://www.dnsfool.com/</uri>
					</author>
		<title type="html"><![CDATA[An Exploit is in the Wild]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DnsFool/~3/gW7vunr-B_s/" />
		<id>http://www.dnsfool.com/?p=31</id>
		<updated>2008-07-24T02:51:32Z</updated>
		<published>2008-07-24T02:49:13Z</published>
		<category scheme="http://www.dnsfool.com" term="Security" /><category scheme="http://www.dnsfool.com" term="Dan Kaminsky" /><category scheme="http://www.dnsfool.com" term="exploits" /><category scheme="http://www.dnsfool.com" term="interviews" /><category scheme="http://www.dnsfool.com" term="Metasploit" />		<summary type="html"><![CDATA[Well that didn&#8217;t take long.
Mere days after the details of the recent DNS attack were made public there is already an exploit out in the wild.  HD Moore and I)ruid have added an exploit to the Metasploit project, a popular penetration testing framework.  These are the good guys, but the bad guys have the same [...]]]></summary>
		<content type="html" xml:base="http://www.dnsfool.com/2008/07/23/an-exploit-is-in-the-wild/">&lt;p&gt;Well that didn&amp;#8217;t take &lt;a href="http://blog.wired.com/27bstroke6/2008/07/dns-exploit-in.html"&gt;long&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Mere days after the details of the recent DNS attack were made public there is already an exploit out in the wild.  HD Moore and I)ruid have added an exploit to the &lt;a href="http://metasploit.com/"&gt;Metasploit&lt;/a&gt; project, a popular penetration testing framework.  These are the good guys, but the bad guys have the same access to the code as everyone else.&lt;/p&gt;
&lt;p&gt;It doesn&amp;#8217;t seem like anyone outside DNS and networking communities really understand how significant this issue is.  Noted DNS expert Cricket Liu has &lt;a href="http://gregness.wordpress.com/2008/07/23/dns-vulnerability-an-exclusive-interview-with-cricket-liu/"&gt;suggested&lt;/a&gt; that this may be the biggest DNS vulnerability in the history of the Internet, and certainly the biggest vulnerability right now.&lt;/p&gt;
&lt;p&gt;Also, there&amp;#8217;s a good interview with Dan Kaminsky over at &lt;a href="http://blog.wired.com/27bstroke6/2008/07/kaminsky-on-how.html"&gt;Wired&lt;/a&gt; where he talks about discovering the vulnerability and reiterates that &amp;#8220;this (attack takes) ten seconds to hijack the net&amp;#8221;.&lt;/p&gt;
&lt;p&gt;Dan provides a &amp;#8220;&lt;a href="http://www.doxpara.com/"&gt;DNS Checker&lt;/a&gt;&amp;#8221; on his website to see if your DNS is vulnerable.  Please go check.  If you find that you are not safe, &lt;a href="http://www.opendns.com/"&gt;OpenDNS&lt;/a&gt; is ready for your traffic.  If you are a network administrator, now might be a good time to consider switching to &lt;a href="http://cr.yp.to/djbdns.html"&gt;djbdns&lt;/a&gt;.&lt;/p&gt;

&lt;span class="slashdigglicious"&gt;
&lt;a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F23%2Fan-exploit-is-in-the-wild%2F&amp;amp;title=An+Exploit+is+in+the+Wild" title="Slashdot It!"&gt;&lt;img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /&gt;&lt;/a&gt;
&lt;a href="http://digg.com/submit?phase=2&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F23%2Fan-exploit-is-in-the-wild%2F&amp;amp;title=An+Exploit+is+in+the+Wild" title="Digg This Story"&gt;&lt;img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /&gt;&lt;/a&gt;
&lt;a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F23%2Fan-exploit-is-in-the-wild%2F&amp;amp;title=An+Exploit+is+in+the+Wild" title="Reddit"&gt;&lt;img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /&gt;&lt;/a&gt;
&lt;a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F23%2Fan-exploit-is-in-the-wild%2F&amp;amp;title=An+Exploit+is+in+the+Wild" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;amp;noui&amp;amp;jump=close&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F23%2Fan-exploit-is-in-the-wild%2F&amp;amp;title=An+Exploit+is+in+the+Wild', 'delicious', 'toolbar=no,width=700,height=400'); return false;"&gt;&lt;img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /&gt;&lt;/a&gt;
&lt;a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F23%2Fan-exploit-is-in-the-wild%2F" title="Share on Facebook"&gt;&lt;img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /&gt;&lt;/a&gt;
&lt;a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F23%2Fan-exploit-is-in-the-wild%2F" title="Add to my Technorati Favorites"&gt;&lt;img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /&gt;&lt;/a&gt;
&lt;a href="http://www.google.com/bookmarks/mark?op=edit&amp;amp;output=popup&amp;amp;bkmk=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F23%2Fan-exploit-is-in-the-wild%2F&amp;amp;title=An+Exploit+is+in+the+Wild" title="Save to Google Bookmarks"&gt;&lt;img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /&gt;&lt;/a&gt;
&lt;a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F23%2Fan-exploit-is-in-the-wild%2F&amp;amp;title=An+Exploit+is+in+the+Wild" title="Stumble it!"&gt;&lt;img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /&gt;&lt;/a&gt;
&lt;/span&gt;&lt;img src="http://feedproxy.google.com/~r/DnsFool/~4/gW7vunr-B_s" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://www.dnsfool.com/2008/07/23/an-exploit-is-in-the-wild/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.dnsfool.com/2008/07/23/an-exploit-is-in-the-wild/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<feedburner:origLink>http://www.dnsfool.com/2008/07/23/an-exploit-is-in-the-wild/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Cory Wright</name>
						<uri>http://www.dnsfool.com/</uri>
					</author>
		<title type="html"><![CDATA[DNS Attack Details Come Early]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DnsFool/~3/YzQ_PXD4Ja8/" />
		<id>http://www.dnsfool.com/?p=30</id>
		<updated>2008-07-24T02:49:48Z</updated>
		<published>2008-07-22T16:58:52Z</published>
		<category scheme="http://www.dnsfool.com" term="Security" /><category scheme="http://www.dnsfool.com" term="Uncategorized" /><category scheme="http://www.dnsfool.com" term="Dan Kaminsky" /><category scheme="http://www.dnsfool.com" term="exploits" />		<summary type="html"><![CDATA[It was just 14 days ago that Dan Kaminsky announced that he had found a critical security flaw in DNS, but that the details would be kept secret until he took the stage at Black Hat on August 6th.  This 29 day gap between the announcement of the discovery and the detailed description of the [...]]]></summary>
		<content type="html" xml:base="http://www.dnsfool.com/2008/07/22/dns-attack-details-come-early/">&lt;p&gt;It was just &lt;a href="http://www.dnsfool.com/2008/07/09/a-big-day-for-dns-security/"&gt;14 days ago&lt;/a&gt; that Dan Kaminsky announced that he had found a critical security flaw in DNS, but that the details would be kept secret until he took the stage at Black Hat on August 6th.  This 29 day gap between the announcement of the discovery and the detailed description of the attacks was to give ISPs and software vendors time to update their systems so that more people on the &amp;#8216;net would be protected when exploits hit the wild.  Also, it would give Dan&amp;#8217;s Black Hat talk a lot of well deserved attention.&lt;/p&gt;
&lt;p&gt;That all changed yesterday when &lt;a href="http://addxorrol.blogspot.com"&gt;Halvar Flake&lt;/a&gt; &lt;a href="http://addxorrol.blogspot.com/2008/07/on-dans-request-for-no-speculation.html"&gt;speculated&lt;/a&gt; what the attack may be.  He wasn&amp;#8217;t sure of it himself, but as it turned out his guess was pretty close.  The &lt;a href="http://www.matasano.com/log/"&gt;Matasano team&lt;/a&gt; posted an entry on their blog that gave details of the attack, which quickly spread around the Internet.  Although the post has since been taken down, and the Matasano team has &lt;a href="http://www.matasano.com/log/1105/regarding-the-post-on-chargen-earlier-today/"&gt;apologized&lt;/a&gt;, the text of the post is &lt;a href="http://blogs.buanzo.com.ar/2008/07/matasano-kaminsky-dns-forgery.html"&gt;available&lt;/a&gt; all around the Internet.  The cat is out of the bag, so everyone needs to make sure their systems are patched right away.&lt;/p&gt;
&lt;p&gt;The attack is interesting indeed, and it is amazing that no one has considered this approach until now.  If you have a few minutes, you may want to &lt;a href="http://blogs.buanzo.com.ar/2008/07/matasano-kaminsky-dns-forgery.html"&gt;read what is available&lt;/a&gt;.&lt;/p&gt;

&lt;span class="slashdigglicious"&gt;
&lt;a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F22%2Fdns-attack-details-come-early%2F&amp;amp;title=DNS+Attack+Details+Come+Early" title="Slashdot It!"&gt;&lt;img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /&gt;&lt;/a&gt;
&lt;a href="http://digg.com/submit?phase=2&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F22%2Fdns-attack-details-come-early%2F&amp;amp;title=DNS+Attack+Details+Come+Early" title="Digg This Story"&gt;&lt;img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /&gt;&lt;/a&gt;
&lt;a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F22%2Fdns-attack-details-come-early%2F&amp;amp;title=DNS+Attack+Details+Come+Early" title="Reddit"&gt;&lt;img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /&gt;&lt;/a&gt;
&lt;a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F22%2Fdns-attack-details-come-early%2F&amp;amp;title=DNS+Attack+Details+Come+Early" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;amp;noui&amp;amp;jump=close&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F22%2Fdns-attack-details-come-early%2F&amp;amp;title=DNS+Attack+Details+Come+Early', 'delicious', 'toolbar=no,width=700,height=400'); return false;"&gt;&lt;img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /&gt;&lt;/a&gt;
&lt;a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F22%2Fdns-attack-details-come-early%2F" title="Share on Facebook"&gt;&lt;img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /&gt;&lt;/a&gt;
&lt;a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F22%2Fdns-attack-details-come-early%2F" title="Add to my Technorati Favorites"&gt;&lt;img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /&gt;&lt;/a&gt;
&lt;a href="http://www.google.com/bookmarks/mark?op=edit&amp;amp;output=popup&amp;amp;bkmk=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F22%2Fdns-attack-details-come-early%2F&amp;amp;title=DNS+Attack+Details+Come+Early" title="Save to Google Bookmarks"&gt;&lt;img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /&gt;&lt;/a&gt;
&lt;a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F22%2Fdns-attack-details-come-early%2F&amp;amp;title=DNS+Attack+Details+Come+Early" title="Stumble it!"&gt;&lt;img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /&gt;&lt;/a&gt;
&lt;/span&gt;&lt;img src="http://feedproxy.google.com/~r/DnsFool/~4/YzQ_PXD4Ja8" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://www.dnsfool.com/2008/07/22/dns-attack-details-come-early/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.dnsfool.com/2008/07/22/dns-attack-details-come-early/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<feedburner:origLink>http://www.dnsfool.com/2008/07/22/dns-attack-details-come-early/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Cory Wright</name>
						<uri>http://www.dnsfool.com/</uri>
					</author>
		<title type="html"><![CDATA[A Big Day for DNS Security]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DnsFool/~3/-92dmIS4V80/" />
		<id>http://www.dnsfool.com/?p=28</id>
		<updated>2008-07-09T19:37:57Z</updated>
		<published>2008-07-09T18:20:30Z</published>
		<category scheme="http://www.dnsfool.com" term="BIND" /><category scheme="http://www.dnsfool.com" term="Security" /><category scheme="http://www.dnsfool.com" term="Server Software" /><category scheme="http://www.dnsfool.com" term="Uncategorized" /><category scheme="http://www.dnsfool.com" term="djbdns" /><category scheme="http://www.dnsfool.com" term="Dan Kaminsky" /><category scheme="http://www.dnsfool.com" term="dnscache" /><category scheme="http://www.dnsfool.com" term="Microsoft" /><category scheme="http://www.dnsfool.com" term="OpenDNS" />		<summary type="html"><![CDATA[Dan Kaminsky has done it again.
Kaminsky found a security vulnerability in the design of DNS itself.  Yea, let that sink in.  The problem was in the DNS protocol, not just certain implementations.  That means BIND is affected (of course), Microsoft DNS is affected, and so on.   A full list of affected systems is available in [...]]]></summary>
		<content type="html" xml:base="http://www.dnsfool.com/2008/07/09/a-big-day-for-dns-security/">&lt;p&gt;Dan Kaminsky has &lt;a href="http://www.doxpara.com/?p=1162"&gt;done it again&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Kaminsky found a &lt;a href="http://news.cnet.com/8301-10789_3-9985815-57.html"&gt;security&lt;/a&gt; &lt;a href="http://securosis.com/2008/07/08/dan-kaminsky-discovers-fundamental-issue-in-dns-massive-multivendor-patch-released/"&gt;vulnerability&lt;/a&gt; in the design of DNS itself.  Yea, let that sink in.  The problem was in the DNS protocol, not just certain implementations.  That means BIND is &lt;a href="http://www.kb.cert.org/vuls/id/252735"&gt;affected&lt;/a&gt; (of course), Microsoft DNS is &lt;a href="http://www.kb.cert.org/vuls/id/484649"&gt;affected&lt;/a&gt;, and so on.   A full list of affected systems is available in the &lt;a href="http://www.kb.cert.org/vuls/id/800113"&gt;CERT advisory&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Something to note is that BIND 8 is &lt;strong&gt;not&lt;/strong&gt; being patched.  If you are running BIND then you should consider upgrading to BIND 9 immediately.&lt;/p&gt;
&lt;p&gt;Several systems are not susceptible, including dnscache from &lt;a href="http://cr.yp.to/djbdns.html"&gt;djbdns&lt;/a&gt;, &lt;a href="http://blog.opendns.com/2008/07/08/opendns-proven-to-be-the-most-secure-dns/"&gt;OpenDNS&lt;/a&gt;, and &lt;a href="http://www.powerdns.com/"&gt;PowerDNS&lt;/a&gt;.  Kaminsky comments on how Dan Bernstein was years ahead of everyone else with djbdns:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;DJB was right. All those years ago, Dan J. Bernstein was right: Source Port Randomization should be standard on every name server in production use.&lt;/p&gt;
&lt;p&gt;There is a fantastic quote that guides a lot of the work I do: Luck is the residue of design. Dan Bernstein is a notably lucky programmer, and that’s no accident. The professor lives and breathes systems engineering in a way that my hackish code aspires to one day experience. DJB got “lucky” here — he ended up defending himself against an attack he almost certainly never encountered.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Here is a PDF of the &lt;a href="http://securosis.com/publications/DNS-Executive-Overview.pdf"&gt;executive overview&lt;/a&gt; of the vulnerability.&lt;/p&gt;
&lt;p&gt;This is being called the largest coordinated security update in the history of the Internet, and it probably is.  Kaminsky coordinated the announcement of the security issue with all the major vendors, allowing everyone to have patches available at the same time and prevent chaos across the Internet.&lt;/p&gt;
&lt;p&gt;The Internet is lucky to have Dan Kaminsky looking out for us.&lt;/p&gt;

&lt;span class="slashdigglicious"&gt;
&lt;a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F09%2Fa-big-day-for-dns-security%2F&amp;amp;title=A+Big+Day+for+DNS+Security" title="Slashdot It!"&gt;&lt;img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /&gt;&lt;/a&gt;
&lt;a href="http://digg.com/submit?phase=2&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F09%2Fa-big-day-for-dns-security%2F&amp;amp;title=A+Big+Day+for+DNS+Security" title="Digg This Story"&gt;&lt;img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /&gt;&lt;/a&gt;
&lt;a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F09%2Fa-big-day-for-dns-security%2F&amp;amp;title=A+Big+Day+for+DNS+Security" title="Reddit"&gt;&lt;img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /&gt;&lt;/a&gt;
&lt;a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F09%2Fa-big-day-for-dns-security%2F&amp;amp;title=A+Big+Day+for+DNS+Security" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;amp;noui&amp;amp;jump=close&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F09%2Fa-big-day-for-dns-security%2F&amp;amp;title=A+Big+Day+for+DNS+Security', 'delicious', 'toolbar=no,width=700,height=400'); return false;"&gt;&lt;img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /&gt;&lt;/a&gt;
&lt;a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F09%2Fa-big-day-for-dns-security%2F" title="Share on Facebook"&gt;&lt;img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /&gt;&lt;/a&gt;
&lt;a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F09%2Fa-big-day-for-dns-security%2F" title="Add to my Technorati Favorites"&gt;&lt;img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /&gt;&lt;/a&gt;
&lt;a href="http://www.google.com/bookmarks/mark?op=edit&amp;amp;output=popup&amp;amp;bkmk=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F09%2Fa-big-day-for-dns-security%2F&amp;amp;title=A+Big+Day+for+DNS+Security" title="Save to Google Bookmarks"&gt;&lt;img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /&gt;&lt;/a&gt;
&lt;a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F07%2F09%2Fa-big-day-for-dns-security%2F&amp;amp;title=A+Big+Day+for+DNS+Security" title="Stumble it!"&gt;&lt;img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /&gt;&lt;/a&gt;
&lt;/span&gt;&lt;img src="http://feedproxy.google.com/~r/DnsFool/~4/-92dmIS4V80" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://www.dnsfool.com/2008/07/09/a-big-day-for-dns-security/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.dnsfool.com/2008/07/09/a-big-day-for-dns-security/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<feedburner:origLink>http://www.dnsfool.com/2008/07/09/a-big-day-for-dns-security/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Cory Wright</name>
						<uri>http://www.dnsfool.com/</uri>
					</author>
		<title type="html"><![CDATA[More Free DNS Utilities]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DnsFool/~3/yy5HUUITU_Q/" />
		<id>http://www.dnsfool.com/?p=25</id>
		<updated>2008-06-27T07:05:36Z</updated>
		<published>2008-06-28T17:02:41Z</published>
		<category scheme="http://www.dnsfool.com" term="Articles" /><category scheme="http://www.dnsfool.com" term="Utilities" />		<summary type="html"><![CDATA[Bite my Bytes has collected a list of free DNS reporting utilities.










]]></summary>
		<content type="html" xml:base="http://www.dnsfool.com/2008/06/28/more-free-dns-utilities/">&lt;p&gt;&lt;a href="http://vidmar.net/weblog/"&gt;Bite my Bytes&lt;/a&gt; has collected a list of &lt;a href="http://vidmar.net/weblog/archive/2008/03/23/free-dns-report-alternatives.aspx"&gt;free DNS reporting utilities&lt;/a&gt;.&lt;/p&gt;

&lt;span class="slashdigglicious"&gt;
&lt;a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F06%2F28%2Fmore-free-dns-utilities%2F&amp;amp;title=More+Free+DNS+Utilities" title="Slashdot It!"&gt;&lt;img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /&gt;&lt;/a&gt;
&lt;a href="http://digg.com/submit?phase=2&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F06%2F28%2Fmore-free-dns-utilities%2F&amp;amp;title=More+Free+DNS+Utilities" title="Digg This Story"&gt;&lt;img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /&gt;&lt;/a&gt;
&lt;a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F06%2F28%2Fmore-free-dns-utilities%2F&amp;amp;title=More+Free+DNS+Utilities" title="Reddit"&gt;&lt;img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /&gt;&lt;/a&gt;
&lt;a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F06%2F28%2Fmore-free-dns-utilities%2F&amp;amp;title=More+Free+DNS+Utilities" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;amp;noui&amp;amp;jump=close&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F06%2F28%2Fmore-free-dns-utilities%2F&amp;amp;title=More+Free+DNS+Utilities', 'delicious', 'toolbar=no,width=700,height=400'); return false;"&gt;&lt;img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /&gt;&lt;/a&gt;
&lt;a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F06%2F28%2Fmore-free-dns-utilities%2F" title="Share on Facebook"&gt;&lt;img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /&gt;&lt;/a&gt;
&lt;a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F06%2F28%2Fmore-free-dns-utilities%2F" title="Add to my Technorati Favorites"&gt;&lt;img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /&gt;&lt;/a&gt;
&lt;a href="http://www.google.com/bookmarks/mark?op=edit&amp;amp;output=popup&amp;amp;bkmk=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F06%2F28%2Fmore-free-dns-utilities%2F&amp;amp;title=More+Free+DNS+Utilities" title="Save to Google Bookmarks"&gt;&lt;img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /&gt;&lt;/a&gt;
&lt;a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F06%2F28%2Fmore-free-dns-utilities%2F&amp;amp;title=More+Free+DNS+Utilities" title="Stumble it!"&gt;&lt;img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /&gt;&lt;/a&gt;
&lt;/span&gt;&lt;img src="http://feedproxy.google.com/~r/DnsFool/~4/yy5HUUITU_Q" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://www.dnsfool.com/2008/06/28/more-free-dns-utilities/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.dnsfool.com/2008/06/28/more-free-dns-utilities/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<feedburner:origLink>http://www.dnsfool.com/2008/06/28/more-free-dns-utilities/</feedburner:origLink></entry>
		<entry>
		<author>
			<name>Cory Wright</name>
						<uri>http://www.dnsfool.com/</uri>
					</author>
		<title type="html"><![CDATA[ICANN and IANA DNS Compromised]]></title>
		<link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DnsFool/~3/uf5i08bn8gE/" />
		<id>http://www.dnsfool.com/?p=24</id>
		<updated>2008-06-27T07:01:32Z</updated>
		<published>2008-06-27T20:55:59Z</published>
		<category scheme="http://www.dnsfool.com" term="Security" /><category scheme="http://www.dnsfool.com" term="Uncategorized" /><category scheme="http://www.dnsfool.com" term="defacement" /><category scheme="http://www.dnsfool.com" term="hacking" /><category scheme="http://www.dnsfool.com" term="IANA" /><category scheme="http://www.dnsfool.com" term="ICANN" />		<summary type="html"><![CDATA[ICANN and IANA were the victims of a DNS redirection attack this week.
Turkish crackers were able to take over the icann.com, icann.net, iana.com and iana-servers.com and redirect them to a hosting account at atspace.com.
Zone-H is hosting a mirror of the defacement.










]]></summary>
		<content type="html" xml:base="http://www.dnsfool.com/2008/06/27/icann-and-iana-dns-compromised/">&lt;p&gt;ICANN and IANA were the &lt;a href="http://www.zone-h.org/content/view/14973/30/"&gt;victims&lt;/a&gt; of a DNS redirection attack this week.&lt;/p&gt;
&lt;p&gt;Turkish crackers were able to take over the icann.com, icann.net, iana.com and iana-servers.com and redirect them to a hosting account at atspace.com.&lt;/p&gt;
&lt;p&gt;Zone-H is hosting a mirror of the &lt;a href="http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,0/id,7635102/"&gt;defacement&lt;/a&gt;.&lt;/p&gt;

&lt;span class="slashdigglicious"&gt;
&lt;a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F06%2F27%2Ficann-and-iana-dns-compromised%2F&amp;amp;title=ICANN+and+IANA+DNS+Compromised" title="Slashdot It!"&gt;&lt;img src="http://slashdot.org/favicon.ico" height="16" width="16" alt="[Slashdot]" /&gt;&lt;/a&gt;
&lt;a href="http://digg.com/submit?phase=2&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F06%2F27%2Ficann-and-iana-dns-compromised%2F&amp;amp;title=ICANN+and+IANA+DNS+Compromised" title="Digg This Story"&gt;&lt;img src="http://digg.com/favicon.ico" width="16" height="16" alt="[Digg]" /&gt;&lt;/a&gt;
&lt;a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F06%2F27%2Ficann-and-iana-dns-compromised%2F&amp;amp;title=ICANN+and+IANA+DNS+Compromised" title="Reddit"&gt;&lt;img src="http://reddit.com/favicon.ico" width="16" height="16" alt="[Reddit]" /&gt;&lt;/a&gt;
&lt;a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F06%2F27%2Ficann-and-iana-dns-compromised%2F&amp;amp;title=ICANN+and+IANA+DNS+Compromised" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;amp;noui&amp;amp;jump=close&amp;amp;url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F06%2F27%2Ficann-and-iana-dns-compromised%2F&amp;amp;title=ICANN+and+IANA+DNS+Compromised', 'delicious', 'toolbar=no,width=700,height=400'); return false;"&gt;&lt;img src="http://images.del.icio.us/static/img/delicious.small.gif" width="16" height="16" alt="[del.icio.us]" /&gt;&lt;/a&gt;
&lt;a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F06%2F27%2Ficann-and-iana-dns-compromised%2F" title="Share on Facebook"&gt;&lt;img src="http://www.facebook.com/favicon.ico" width="16" height="16" alt="[Facebook]" /&gt;&lt;/a&gt;
&lt;a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F06%2F27%2Ficann-and-iana-dns-compromised%2F" title="Add to my Technorati Favorites"&gt;&lt;img src="http://technorati.com/favicon.ico" width="16" height="16" alt="[Technorati]" /&gt;&lt;/a&gt;
&lt;a href="http://www.google.com/bookmarks/mark?op=edit&amp;amp;output=popup&amp;amp;bkmk=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F06%2F27%2Ficann-and-iana-dns-compromised%2F&amp;amp;title=ICANN+and+IANA+DNS+Compromised" title="Save to Google Bookmarks"&gt;&lt;img src="http://www.google.com/favicon.ico" width="16" height="16" alt="[Google]" /&gt;&lt;/a&gt;
&lt;a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.dnsfool.com%2F2008%2F06%2F27%2Ficann-and-iana-dns-compromised%2F&amp;amp;title=ICANN+and+IANA+DNS+Compromised" title="Stumble it!"&gt;&lt;img src="http://www.stumbleupon.com/favicon.ico" width="16" height="16" alt="[StumbleUpon]" /&gt;&lt;/a&gt;
&lt;/span&gt;&lt;img src="http://feedproxy.google.com/~r/DnsFool/~4/uf5i08bn8gE" height="1" width="1"/&gt;</content>
		<link rel="replies" type="text/html" href="http://www.dnsfool.com/2008/06/27/icann-and-iana-dns-compromised/#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.dnsfool.com/2008/06/27/icann-and-iana-dns-compromised/feed/atom/" thr:count="0" />
		<thr:total>0</thr:total>
	<feedburner:origLink>http://www.dnsfool.com/2008/06/27/icann-and-iana-dns-compromised/</feedburner:origLink></entry>
	</feed>
