• Amused
  • Angry
  • Annoyed
  • Awesome
  • Bemused
  • Cocky
  • Cool
  • Crazy
  • Crying
  • Depressed
  • Down
  • Drunk
  • Embarrased
  • Enraged
  • Friendly
  • Geeky
  • Godly
  • Happy
  • Hateful
  • Hungry
  • Innocent
  • Meh
  • Piratey
  • Poorly
  • Sad
  • Secret
  • Shy
  • Sneaky
  • Tired
  • Wtf
  • Results 1 to 9 of 9

    Thread: Welcome to phishing.co- I mean your bank! yourbank.com!

    1. #1
      Doing Everything in Restricted Perfection Administrator
      Mythril Wings of Service
      This user has no status.
       
      I am:
      Meh
       
      Taskmage's Avatar
      Join Date
      Dec 2003
      Posts
      7,029
      Thanks
      921
      Thanked 2,446x in 1,287 Posts

      Welcome to phishing.co- I mean your bank! yourbank.com!

      Apparently, internets are really easy to hax right now.

      http://www.npr.org/templates/story/s...oryId=92956413

      A few months ago, Internet security expert Dan Kaminsky discovered a major problem with the basic wiring of the Internet — one that could easily be exploited by hackers. It has to do with what's known as the domain name system, or DNS.

      Kaminsky, who works for the Internet security company IO Active and is a consultant for Microsoft, tells Andrea Seabrook that he stumbled upon the flaw while tinkering with a way to make the Internet faster.

      "You want to talk sinking feelings," he says. "This was a bug that was going to take months and month and months of work."

      Essentially, the DNS contains a design flaw that could enable hackers to switch the Web site you're directed to when you type a URL into your Web browser. Without your knowledge, you could be transferred to a fake Web site that tries to steal your personal information.

      When Kaminsky discovered the problem, he called a secret meeting in March of some of the world's Internet giants — Microsoft, Cisco, Linux — in Redmond, Wash., to come up with a security patch.

      Why the big need for secrecy? "We all had something to lose," he says.

      To check whether your company or Internet service provider's DNS server has been patched, Kaminsky recommends taking these steps:

      Run the DNS server check at DNS Stuff or at Kaminsky's blog.

      If the server is vulnerable, Kaminsky suggests e-mailing your ISP or your company's IT department and encouraging them to add a patch. Kaminsky also recommends switching your personal computer to use OpenDNS, a free network service. More information and instructions are available at opendns.com.

      "The average consumer shouldn't have to worry about this," he says. "Right now, it's an open question whether the Internet that's being provided is the Internet that's actually what the customer expects."

    2. #AD


      Advertisement
       

    3. #2
      Now With More Y! Bronze Star
      This user has no status.
       
      I am:
      ----
       
      Callisto's Avatar
      Join Date
      Jun 2007
      Location
      Chicago Suburbs
      Posts
      2,548
      Thanks
      200
      Thanked 651x in 374 Posts

      Re: Welcome to phishing.co- I mean your bank! yourbank.com!

      Well good thing they went and told everyone about it, just in case there were a few hackers that didn't know. Wouldn't want them to miss out on an opportunity just in case some DNS servers hadn't been patched yet.
      Callysto of RamuhCaithsith - 75 RDM / BRD / COR / PLD / WAR / SCH / DRK

      Formerly Callisto of Ramuh. | Retired 5.28.10

      Callisto Broadwurst of Palamecia

      To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

    4. #3
      Dictionary Allied Ribbon of Glory
      This user has no status.
       
      I am:
      ----
       

      Join Date
      Jul 2004
      Location
      Warrior
      Posts
      2,131
      Thanks
      268
      Thanked 399x in 247 Posts

      Re: Welcome to phishing.co- I mean your bank! yourbank.com!

      That's why it was a secret. They wanted it fixed before it got discovered. But a boat this big was sure to develop some leaks on a Titanic scale.
      "And if he left off dreaming about you, where do you suppose you'd be?"

    5. #4
      Now With More Y! Bronze Star
      This user has no status.
       
      I am:
      ----
       
      Callisto's Avatar
      Join Date
      Jun 2007
      Location
      Chicago Suburbs
      Posts
      2,548
      Thanks
      200
      Thanked 651x in 374 Posts

      Re: Welcome to phishing.co- I mean your bank! yourbank.com!

      Except they said it might not be all the way fixed for every ISP yet, lol. That's like the Secretary of Defense saying, "We had these huge security holes, and most have been covered up before the terrists found out, but there may still be 3 so see if you can find them!"
      Callysto of RamuhCaithsith - 75 RDM / BRD / COR / PLD / WAR / SCH / DRK

      Formerly Callisto of Ramuh. | Retired 5.28.10

      Callisto Broadwurst of Palamecia

      To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

    6. #5
      better this time Dawnlight Medal
      This user has no status.
       
      I am:
      Awesome
       
      Feba's Avatar
      Join Date
      Oct 2004
      Posts
      9,924
      Thanks
      2,310
      Thanked 3,090x in 2,023 Posts

      Re: Welcome to phishing.co- I mean your bank! yourbank.com!

      Callisto: This is common practice. Find a serious security hole, fix it, and then announce that it's fixed. Security through obscurity rarely works; it wouldn't have lasted long at all in this case.

      To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

    7. #6
      Doing Everything in Restricted Perfection Administrator
      Mythril Wings of Service
      This user has no status.
       
      I am:
      Meh
       
      Taskmage's Avatar
      Join Date
      Dec 2003
      Posts
      7,029
      Thanks
      921
      Thanked 2,446x in 1,287 Posts

      Re: Welcome to phishing.co- I mean your bank! yourbank.com!

      It's not fixed though. About 50% of ISPs are still vulnerable. But they didn't publicly announce it until there was a major leak about the problem anyway, which was inevitable considering how many large companies were involved.

    8. #7
      better this time Dawnlight Medal
      This user has no status.
       
      I am:
      Awesome
       
      Feba's Avatar
      Join Date
      Oct 2004
      Posts
      9,924
      Thanks
      2,310
      Thanked 3,090x in 2,023 Posts

      Re: Welcome to phishing.co- I mean your bank! yourbank.com!

      Quote Originally Posted by Taskmage View Post
      It's not fixed though.
      Yes, it is. Whether the fix is implemented or not is irrelevant.

      Do you realize how many vulnerabilities are announced every day, which are open doors for crackers if you don't update your system constantly?

      To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

    9. #8
      Now With More Y! Bronze Star
      This user has no status.
       
      I am:
      ----
       
      Callisto's Avatar
      Join Date
      Jun 2007
      Location
      Chicago Suburbs
      Posts
      2,548
      Thanks
      200
      Thanked 651x in 374 Posts

      Re: Welcome to phishing.co- I mean your bank! yourbank.com!

      I'm aware of that, but it's not like 'There was a Flash exploit, update your Flash player!', this is more like 'There was a DNS exploit, hope your ISP has updated!'. That's the part that bugged me.
      Callysto of RamuhCaithsith - 75 RDM / BRD / COR / PLD / WAR / SCH / DRK

      Formerly Callisto of Ramuh. | Retired 5.28.10

      Callisto Broadwurst of Palamecia

      To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

    10. #9
      Voodoo Black Magic Priest Brass Wings of Service
      This user has no status.
       
      I am:
      ----
       
      Mhurron's Avatar
      Join Date
      May 2006
      Location
      Best Carolina
      Posts
      6,606
      Thanks
      238
      Thanked 2,946x in 1,648 Posts

      Re: Welcome to phishing.co- I mean your bank! yourbank.com!

      Quote Originally Posted by Callisto View Post
      I'm aware of that, but it's not like 'There was a Flash exploit, update your Flash player!', this is more like 'There was a DNS exploit, hope your ISP has updated!'. That's the part that bugged me.
      They were notified in time to patch. This also doesn't just affect ISP's.

      To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.



      To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


      loose

    Tags for this Thread

    Posting Permissions

    • You may not post new threads
    • You may not post replies
    • You may not post attachments
    • You may not edit your posts
    •