'Major internet security flaw' published

24th July 2008

The details of a major flaw in the internet's DNS were released by accident several weeks before they should have been published, it has been reported.

According to Infoworld.com, IOActive researcher Dan Kaminsky discovered the flaw earlier this year and has since worked with Microsoft, Cisco, and the Internet Systems Consortium to help resolve it.

Two weeks ago, a patch for the problem was released and corporate users were advised to patch their DNS systems, and keep details of the problem quiet until it was resolved, with Mr Kaminsky planning to unveil an analysis of the issue at an upcoming conference.

However, the news provider notes researchers exposed the problem prior to the event and had their findings accidentally confirmed by Matasano Security, a vendor that had been briefed on the issue via its blog.

Meanwhile, PC World has reported that a code for the attack has been released by developers of the Metasploit hacking toolkit.

A recent Connect survey found that the two major concerns about outsourcing services like IT support were 'loss of control' (56 per cent) and 'budget over-runs' (43 per cent)