<?xml version="1.0" encoding="ISO-8859-1"?>
<!-- generator="HardwareAnalysis.Com" -->
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="">
        <title>Hardware Analysis - Major world-wide DNS flaw could put your computer at risk</title>
        <description>Hardware Analysis Community Forums</description>
        <link>http://www.hardwareanalysis.com/content/topic/71959/</link>
        <image rdf:resource="http://media.hardwareanalysis.com/halogo.gif" />
       <dc:date>2008-12-03T19:24:29-05:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/71959/#540238"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/71959/#540207"/>
                <rdf:li rdf:resource="http://www.hardwareanalysis.com/content/topic/71959/#0"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="http://media.hardwareanalysis.com/halogo.gif">
        <title>Hardware Analysis</title>
        <link>http://www.hardwareanalysis.com/content/topic/71959/</link>
        <url>http://media.hardwareanalysis.com/halogo.gif</url>
    </image>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/71959/#540238">
        <dc:format>text/html</dc:format>
        <dc:date>2008-07-10T23:57:28-05:00</dc:date>
        <dc:creator>Gerritt</dc:creator>
        <title>Re: Major world-wide DNS flaw could put your computer at risk</title>
        <link>http://www.hardwareanalysis.com/content/topic/71959/#540238</link>
        <description>DNS has always been an issue with security on the internet.&lt;br /&gt;
For unsecured DNS, the practice of increasing the record number in the DNS entry would actually permit the override of any other DNS record, with no checks to the primary owners record base.  This could, would, does lead to a malicious user to hijack at least some if not all of your traffic based upon DNS name resolution.&lt;br /&gt;
If you maintain a DNS server that supports a all record lookup via nslookup or dig, then you are vulnerable.  Do you know there are still folks out there running buisnesses with static IPs that are still supporting the finger protocol?!?!&lt;br /&gt;
Whats the most scary to me, is that Developers and the Companies associated with them seem to be the most &amp;quot;accessable&amp;quot; or vulnerable to these types of attacks, and they have entry points into major corporations.  Most Coders do not understand the underlying risk that they are exposing thier clientelle to.  This is one of the reasons I have a job.&lt;br /&gt;
</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/71959/#540207">
        <dc:format>text/html</dc:format>
        <dc:date>2008-07-10T21:21:55-05:00</dc:date>
        <dc:creator>angryhippy</dc:creator>
        <title>Re: Major world-wide DNS flaw could put your computer at risk</title>
        <link>http://www.hardwareanalysis.com/content/topic/71959/#540207</link>
        <description>Wednesday July 9, 2008 &lt;br /&gt;
Microsoft DNS Patch Grounds ZoneAlarm Users &lt;br /&gt;
 &lt;br /&gt;
One of Tuesday's Microsoft patches causes ZoneAlarm users to lose Internet connectivity. The patch appears to be MS08-037 (Vulnerabilities in DNS Could Allow Spoofing), which was part of an Internet-wide fix of a common design flaw in DNS implementations&lt;br /&gt;
&lt;br /&gt;
ZoneLabs has issued a workaround for users suffering from the problem. You have three options:&lt;br /&gt;
&lt;br /&gt;
1.Move Internet Zone slider to Medium&lt;br /&gt;
&lt;br /&gt;
Navigate to the &amp;quot;ZoneAlarm Firewall&amp;quot; panel&lt;br /&gt;
&lt;br /&gt;
Click on the &amp;quot;Overview&amp;quot; tab&lt;br /&gt;
&lt;br /&gt;
Move the &amp;quot;Internet Zone&amp;quot; slider to medium&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2. Uninstall the hotfix&lt;br /&gt;
&lt;br /&gt;
Click the &amp;quot;Start Menu&amp;quot; &lt;br /&gt;
&lt;br /&gt;
Click &amp;quot;Control Panel&amp;quot;, or click &amp;quot;Settings&amp;quot; then &amp;quot;Control Panel&amp;quot; &lt;br /&gt;
&lt;br /&gt;
Click on &amp;quot;Add or Remove Programs&amp;quot; &lt;br /&gt;
&lt;br /&gt;
On the top of the add/remove programs dialog box, you should see a checkbox that says &amp;quot;show updates&amp;quot;. Select this checkbox&lt;br /&gt;
&lt;br /&gt;
Scroll down until you see &amp;quot;Security update for Windows (KB951748)&amp;quot; &lt;br /&gt;
&lt;br /&gt;
Click &amp;quot;Remove&amp;quot; to uninstall the hotfix &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3. (advanced technical skills required): Add your DNS servers to trusted zone &lt;br /&gt;
&lt;br /&gt;
From the &amp;quot;Overview&amp;quot; panel, select the &amp;quot;Firewall&amp;quot; panel then click on the &amp;quot;Zones&amp;quot; tab &lt;br /&gt;
&lt;br /&gt;
Click &amp;quot;Add&amp;quot;, then select &amp;quot;IP address&amp;quot; from the shortcut menu. The Add IP Address dialog appears. Select &amp;quot;trusted&amp;quot; from the Zone drop-down list&lt;br /&gt;
&lt;br /&gt;
Type the IP address and a description in the boxes provided, then click &amp;quot;OK&amp;quot; &lt;br /&gt;
&lt;br /&gt;
If you are not sure what IP addresses to add:&lt;br /&gt;
&lt;br /&gt;
Click the Start Menu &lt;br /&gt;
&lt;br /&gt;
Click on Run. Type &amp;quot;cmd.exe&amp;quot; &lt;br /&gt;
&lt;br /&gt;
In the command prompt type: &amp;quot;ipconfig /all&amp;quot;. Look for DNS Server(s) in the output of the command &lt;br /&gt;
&lt;br /&gt;
For each IP address listed, navigate to the &amp;quot;Zones&amp;quot; panel of the &amp;quot;Firewall&amp;quot; tab, add the IP address, select &amp;quot;Trusted Zone&amp;quot;, and press &amp;quot;Apply&amp;quot;&lt;br /&gt;
&lt;br /&gt;
After you are done adding DNS servers click the &amp;quot;Apply&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
Also chck with zone alarm for fixes.&lt;br /&gt;
Source:&lt;a class=&quot;ext&quot; href=&quot;/action/r/http://snipurl.com/2wcry&quot; target=&quot;_blank&quot;&gt;http://snipurl.com/2wcry&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;&lt;b&gt;LOL So what else is new?&lt;/b&gt;&lt;/i&gt;</description>
    </item>
    <item rdf:about="http://www.hardwareanalysis.com/content/topic/71959/#0">
        <dc:format>text/html</dc:format>
        <dc:date>2008-07-09T16:46:49-05:00</dc:date>
        <dc:creator>john albrich</dc:creator>
        <title>Major world-wide DNS flaw could put your computer at risk</title>
        <link>http://www.hardwareanalysis.com/content/topic/71959/#0</link>
        <description>I checked my DNS (&amp;quot;XYZ&amp;quot; via ISP COX broadband internet) and it IS still identified as vulnerable to this threat. Note: your ISP may have more than one DNS available.&lt;br /&gt;
&lt;br /&gt;
If you want additional details on the IP address that was provided by the tool at &lt;a class=&quot;ext&quot; target=&quot;_blank&quot; href=&quot;/action/r/http://doxpara.com&quot;&gt;doxpara.com&lt;/a&gt; (if any) you go to this page, &lt;a class=&quot;ext&quot; href=&quot;/action/r/http://www.ip2location.com/&quot; target=&quot;_blank&quot;&gt;http://www.ip2location.com/&lt;/a&gt; and enter that number into the field provided at the upper right-hand side of the web-page, and then click on the &amp;quot;Find Location&amp;quot; button. It will ID the DNS and service provider information.&lt;br /&gt;
====================================&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;a class=&quot;ext&quot; href=&quot;/action/r/http://www.breitbart.com/article.php?id=080709124916.zxdxcmkx&amp;amp;show_article=1&quot; target=&quot;_blank&quot;&gt;http://www.breitbart.com/article.php?id=080709124916.zxdxcmkx&amp;..._article=1&lt;/a&gt;&lt;br /&gt;
Internet flaw could let hackers take over the Web 	&lt;br /&gt;
Jul 9 08:49 AM US/Eastern&lt;br /&gt;
&lt;br /&gt;
Recently, a significant threat to DNS, the system that translates names you can remember (such as &lt;a class=&quot;ext&quot; href=&quot;/action/r/http://www.doxpara.com&quot; target=&quot;_blank&quot;&gt;http://www.doxpara.com&lt;/a&gt;) to numbers the Internet can route (66.240.226.139) was discovered, that &lt;b&gt;allows malicious people to impersonate almost any website on the Internet&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
To find out if the DNS server you use is vulnerable, go to the doxpara website below, and click on the &amp;quot;Check My DNS&amp;quot; button. &lt;br /&gt;
&lt;br /&gt;
Kaminsky built a web page, &lt;a class=&quot;ext&quot; href=&quot;/action/r/http://www.doxpara.com,&quot; target=&quot;_blank&quot;&gt;http://www.doxpara.com,&lt;/a&gt; where people can find out whether their computers have the DNS vulnerability.&lt;br /&gt;
&lt;br /&gt;
Automated updating should protect most personal computers. Microsoft released the fix in a software update package Tuesday.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
edit-add instructs on finding more details about the DNS IP address.</description>
    </item>
</rdf:RDF>
