...
首页> 外文期刊>Information Week >DNS Threat Revealed
【24h】

DNS Threat Revealed

机译:显示DNS威胁

获取原文
获取原文并翻译 | 示例
           

摘要

Us-cert, the government's cybersecurity arm, last week warned of a serious weakness in the Domain Name System protocol that could be used to send Internet users to malicious sites. In an unusual move that reflects the seriousness of the flaw, news of the vulnerability was delayed for months to give Microsoft, Cisco, Sun, and other software vendors -more than 80 were affected-time to release fixes. Details about the vulnerability and how to exploit it are being deliberately withheld, but Amol Sarwate, manager of vulnerability labs at Qualys, says the issue appears to be that the transaction ID generated in a DNS request-when querying a DNS server to link an IP address with an Internet domain name-is insufficiently random to avoid being guessed by a knowledgeable attacker.
机译:政府网络安全部门US-cert上周警告称,域名系统协议存在严重缺陷,可用于将Internet用户发送到恶意站点。反映该漏洞严重性的不寻常举动是,该漏洞的消息被推迟了几个月,以使微软,思科,Sun和其他软件供应商受益。受影响的发布补丁的时间超过了80个。故意保留了有关漏洞及其利用方法的详细信息,但是Qualys漏洞实验室经理Amol Sarwate表示,问题似乎是在查询DNS服务器链接IP时DNS请求中生成的事务ID。具有Internet域名的地址-随机性不足,无法避免被知识渊博的攻击者猜中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号