AGL 40.21 Increased By ▲ 0.18 (0.45%)
AIRLINK 127.64 Decreased By ▼ -0.06 (-0.05%)
BOP 6.67 Increased By ▲ 0.06 (0.91%)
CNERGY 4.45 Decreased By ▼ -0.15 (-3.26%)
DCL 8.73 Decreased By ▼ -0.06 (-0.68%)
DFML 41.16 Decreased By ▼ -0.42 (-1.01%)
DGKC 86.11 Increased By ▲ 0.32 (0.37%)
FCCL 32.56 Increased By ▲ 0.07 (0.22%)
FFBL 64.38 Increased By ▲ 0.35 (0.55%)
FFL 11.61 Increased By ▲ 1.06 (10.05%)
HUBC 112.46 Increased By ▲ 1.69 (1.53%)
HUMNL 14.81 Decreased By ▼ -0.26 (-1.73%)
KEL 5.04 Increased By ▲ 0.16 (3.28%)
KOSM 7.36 Decreased By ▼ -0.09 (-1.21%)
MLCF 40.33 Decreased By ▼ -0.19 (-0.47%)
NBP 61.08 Increased By ▲ 0.03 (0.05%)
OGDC 194.18 Decreased By ▼ -0.69 (-0.35%)
PAEL 26.91 Decreased By ▼ -0.60 (-2.18%)
PIBTL 7.28 Decreased By ▼ -0.53 (-6.79%)
PPL 152.68 Increased By ▲ 0.15 (0.1%)
PRL 26.22 Decreased By ▼ -0.36 (-1.35%)
PTC 16.14 Decreased By ▼ -0.12 (-0.74%)
SEARL 85.70 Increased By ▲ 1.56 (1.85%)
TELE 7.67 Decreased By ▼ -0.29 (-3.64%)
TOMCL 36.47 Decreased By ▼ -0.13 (-0.36%)
TPLP 8.79 Increased By ▲ 0.13 (1.5%)
TREET 16.84 Decreased By ▼ -0.82 (-4.64%)
TRG 62.74 Increased By ▲ 4.12 (7.03%)
UNITY 28.20 Increased By ▲ 1.34 (4.99%)
WTL 1.34 Decreased By ▼ -0.04 (-2.9%)
BR100 10,086 Increased By 85.5 (0.85%)
BR30 31,170 Increased By 168.1 (0.54%)
KSE100 94,764 Increased By 571.8 (0.61%)
KSE30 29,410 Increased By 209 (0.72%)

Internet security researchers on Thursday warned that hackers have caught on to a "critical" flaw that lets them control traffic on the Internet.
An elite squad of computer industry engineers that laboured in secret to solve the problem released a software "patch" two weeks ago and sought to keep details of the vulnerability hidden at least a month to give people time to protect computers from attacks.
"We are in a lot of trouble," said IOActive security specialist Dan Kaminsky, who stumbled upon the Domain Name System (DNS) vulnerability about six months ago and reached out to industry giants to collaborate on a solution.
DNS is used by every computer that links to the Internet and works similar to a telephone system routing calls to proper numbers, in this case the online numerical addresses of websites. The vulnerability allows "cache poisoning" attacks that tinker with data stored in computer memory caches that relay Internet traffic to its destination.
Attackers could use the vulnerability to route Internet users wherever the hackers wanted, no matter what website address is typed into a web browser. The threat is greatest for business computers handling online traffic or hosting websites, according to security researchers.
The flaw is a boon for "phishing" cons that involve leading people to imitation web pages of businesses such as bank or credit card companies to trick them into disclosing account numbers, passwords and other information.
"I was not intentionally seeking to cause anything that could break the Internet," Kaminsky said Thursday during a conference call with peers and media. "It's a little weird to talk about it out loud." Kaminsky built a web page, www.doxpara.com, where people can find out whether their computers have the DNS vulnerability. As of Thursday, slightly more than half the computers tested at the website still needed to be patched. The US Computer Emergency Readiness Team (CERT), a joint government-private sector security partnership, is among the chorus urging people to quickly protect computers linked to the Internet.

Copyright Agence France-Presse, 2008

Comments

Comments are closed.