Newsletters Welcome, Guest Log In | Register

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

1

China Netcom Poisoned by DNS Flaw

Posted by Kara Reeder Aug 22, 2008 10:18:40 AM

China Netcom, one of the country's largest Internet service providers, has fallen victim to the DNS flaw, according to InformationWeek.

 

Websense discovered the attack, which will direct users that mistype a Web address to a malicious site. Stephan Chenette, manager of Websense security labs, says the attack is clever in that rather than redirecting all traffic, it only redirects mistyped Web addresses.

 

According to Chenette, pretty much all Microsoft users that haven't gotten the latest patch are vulnerable, which is a particularly big problem in China as many users have pirated software or software that is not up-to-date.

 

Shortly after security researcher Dan Kaminsky announced he discovered the flaw and was working with vendors to release a synchronized update, he warned that the flaw was being weaponized in the field.

Add a comment Leave a comment on this blog post.
Aug 23, 2008 3:02 AM Guest mtuo  says:

yeah! I come from china.

IT Security Manual Template

Immediately download a customizable set of documents and templates that covers every aspect of IT Security. These templates are compliant with ISO27000, HIPPAA and Sarbanes oxley standards.

Learn more >

The IT Governance and Compliance Toolkit

This Toolkit is a collection of templates and instructional documents that help you assess and establish the crucial policies that you need to operate a secure and compliant IT organization.

Learn more >

Buyer's Guide for Enterprise Single Sign-On

This white paper offers a thorough checklist that should enable potential ESSO implementers to deploy the right ESSO solution, to help eliminate sign-on problems, reduce helpdesk costs, maximize user productivity, strengthen security, simplify administration and accelerate regulatory compliance.

Seven Design Requirements for Web 2.0 Threat Prevention

This white paper outlines the new Web 2.0 threats, explains why most existing security solutions can't provide adequate protection, and proposes seven design requirements for Web 2.0 threat protection.

Data Loss Protection

Data-loss prevention tactics, technologies and best practices to protect your sensitive and valuable company data.

Security Information and Event Management

Best practices, strategies and technologies to help you use security information and event log management efficiently and effectively in order to get business value in terms of increased security, reduced risk, regulatory compliance and increased business agility.

Security SaaS Solutions

Hosted security solutions that not only protect your data, but reduce your security management TCO, as well.