Translate

Thursday, November 18, 2010

Crime: Computer Hackers

Computer Hackers: Internet Flaw Sparks Biggest Security Fix in Web History

Microsoft among companies announcing action against hijacking internet scam by closing loophole

A flaw in the way the internet works has prompted the "largest security update" in the history of the web, and fears of millions of people remaining exposed to criminals and malicious hackers.

Microsoft was among net companies yesterday which announced action to close the loophole that has potentially affected every site on the web.

Dan Kaminsky, a director at the American security specialist IO Active, who immediately contacted big technology firms to alert them to the problem, spotted the bug this year.

The scam involved hijacking internet addresses and sending surfers to websites other than those they intended to see. By this route criminals stood the chance of tricking victims into handing over personal details or making payments to the wrong people.

Details of the bug, which uses a technique known as “cache poisoning”, has not been made public. The idea is to let firms find a solution before hackers learn how to exploit the situation further.

"Computers use the equivalent of address books to figure out where they need to go on the web. This attack could compromise that by attacking the servers that give out the addresses," said Rich Mogull, of the US-based firm Securosis.

Although there is no evidence of the bug being exploited by hackers, news of the flaw drew an unprecedented response from the technology industry. Large companies, including Microsoft and Cisco Systems, scrambled to fix the problem.

"This is the largest synchronized security update in the history of the Internet," said Kaminsky. "The severity of this bug is shown by the number of those who are on board with patches."

As fixing the problem is largely the duty of those who operate the millions of web servers, which hold all the information on the Internet, rather than those who use the web, most computer users will not have to do anything.

However, a failure to update software could mean surfers still being at risk. And the fixes may not make things entirely safe. The US Computer Emergency Readiness Team, an American agency which deals with security breaches, said that even the changes put forward by Microsoft and others would not remove all possibilities of a hijack. "It is important to note that without changes to the DNS [domain name system] protocol these mitigations cannot completely prevent cache poisoning," said the agency on its website.

Kaminsky said he would reveal more details about the problem at a computer security conference next month. It is not the first time that significant flaws at the heart of the internet have been exposed. Last week servers belonging to Icann, the group which administrates the way names on the net are handed out, were briefly hit by Turkish hackers. A group calling itself NetDevilz broke into the Icann website and replaced the organization's normal web pages with angry messages.

So-called cyber-terrorism - including hacking attacks and concerted attempts to bring down government websites - have gained a high profile in recent months, leading to NATO agreeing to fund a cyber-crime prevention center in east Europe. This week a report by the US Senate's armed services committee emphasized the need for greater security.

"We assess that nations ... have the technical capabilities to target and disrupt elements of the US information infrastructure."

1 comment:

Please be considerate of others, and please do not post any comment that has profane language. Please Do Not post Spam. Thank you.

Powered By Blogger

Labels

Abduction (2) Abuse (3) Advertisement (1) Agency By City (1) Agency Service Provided Beyond Survival Sexual Assault (1) Aggressive Driving (1) Alcohol (1) ALZHEIMER'S DISEASE (2) Anti-Fraud (2) Aspartame (1) Assault (1) Auto Theft Prevention (9) Better Life (1) Books (1) Bribery (1) Bullying (1) Burglary (30) Car Theft (8) Carjackng (2) Child Molestation (5) Child Sexual Abuse (1) Child Abuse (2) Child Kidnapping (3) Child Porn (1) Child Rape (3) Child Safety (18) Child Sexual Abuse (9) Child Violence (1) Classification of Crime (1) Club Drugs (1) College (1) Computer (4) Computer Criime (4) Computer Crime (8) Confessions (2) CONFESSIONS (7) Cons (2) Credit Card Scams (2) Crime (11) Crime Index (3) Crime Prevention Tips (14) Crime Tips (31) Criminal Activity (1) Criminal Behavior (3) Crimm (1) Cyber-Stalking (2) Dating Violence (1) Deviant Behavior (6) Domestic Violence (7) E-Scams And Warnings (1) Elder Abuse (9) Elder Scams (1) Empathy (1) Extortion (1) Eyeballing a Shopping Center (1) Facebook (9) Fakes (1) Family Security (1) Fat People (1) FBI (1) Federal Law (1) Financial (2) Fire (1) Fraud (9) FREE (4) Fun and Games (1) Global Crime on World Wide Net (1) Golden Rules (1) Government (1) Guilt (2) Hackers (1) Harassment (1) Help (2) Help Needed (1) Home Invasion (2) How to Prevent Rape (1) ID Theft (96) Info. (1) Intent (1) Internet Crime (6) Internet Fraud (1) Internet Fraud and Scams (7) Internet Predators (1) Internet Security (30) Jobs (1) Kidnapping (1) Larceny (2) Laughs (3) Law (1) Medician and Law (1) Megans Law (1) Mental Health (1) Mental Health Sexual (1) Misc. (11) Missing Cash (5) Missing Money (1) Moner Matters (1) Money Matters (1) Money Saving Tips (11) Motive (1) Murder (1) Note from Birdy (1) Older Adults (1) Opinion (1) Opinions about this article are Welcome. (1) Personal Note (2) Personal Security and Safety (12) Porn (1) Prevention (2) Price of Crime (1) Private Life (1) Protect Our Kids (1) Protect Yourself (1) Protection Order (1) Psychopath (1) Psychopathy (1) Psychosis (1) PTSD (2) Punishment (1) Quoted Text (1) Rape (66) Ravishment (4) Read Me (1) Recovery (1) Regret (1) Religious Rape (1) Remorse (1) Road Rage (1) Robbery (5) Safety (2) SCAM (19) Scams (62) Schemes (1) Secrets (2) Security Threats (1) Serial Killer (2) Serial Killer/Rapist (4) Serial Killers (2) Sexual Assault (16) Sexual Assault - Spanish Version (3) Sexual Assault against Females (5) Sexual Education (1) Sexual Harassment (1) Sexual Trauma. (4) Shame (1) Sociopath (2) Sociopathy (1) Spam (6) Spyware (1) SSN's (4) Stalking (1) State Law (1) Stress (1) Survival (2) Sympathy (1) Tax Evasion (1) Theft (13) this Eve (1) Tips (13) Tips on Prevention (14) Travel (5) Tricks (1) Twitter (1) Unemployment (1) Victim (1) Victim Rights (9) Victimization (1) Violence against Women (1) Violence. (3) vs. (1) Vulnerable Victims (1) What Not To Buy (2)