Skip to main content /TECH with IDG.net
CNN.com /TECH
CNN TV
EDITIONS

Study: Domain Name System security still lax

Network World Fusion

(IDG) -- Companies rushed to upgrade Domain Name System software after warnings were issued in late January about a flaw in widely used DNS software. In the past weeks, however, upgrading has come to a halt, concludes the Iceland DNS consultancy and software firm Men & Mice.

Men & Mice tested the DNS systems for the Web sites of Fortune 1000 companies and random, .com domains at set dates after the alerts were released. The results were made public on the company's site. The Computer Emergency Response Team (CERT) at Carnegie Mellon University, meanwhile, said this week that it has begun receiving reports of Berkeley Internet Name Domain (BIND) holes being successfully exploited.

MESSAGE BOARD
 
IDG.net INFOCENTER
IDG.net
Features
Visit an IDG site


IDG.net search



BIND, distributed free by the Internet Software Consortium (ISC), is software run by companies and Internet service providers to translate text-based Internet addresses into numbered IP addresses. Versions including both 4.9.x prior to 4.9.8 and 8.2.x are not secure, according to CERT.

The day after CERT and Network Associates' PGP security subsidiary sent out the warnings, 33.3 percent of Fortune 1000 sites were using a bad version of BIND and 40.27 percent of .com domains were vulnerable. A week later, the figures were down to 17.4 percent and 16.73 percent, respectively, Men & Mice said.

After the big drop, which Men & Mice attributed to the "extensive media coverage" about the issue, the pace of companies updating DNS software fell sharply. The latest tests, run on Feb. 21, showed that 12.4 percent of Fortune 1000 companies and 13.1 percent of dot-coms were still using insecure DNS software.

Men & Mice ran a similar test for DNS software used in the national domains of Germany (.de) and Switzerland (.ch) and the U.K.'s commercial domain (.co.uk). Software for those domains was updated, but 15.29 percent of DNS servers in Germany, 11.54 percent in Switzerland and 9.87 percent of the U.K.'s commercial domains remained vulnerable as of Feb. 21.




RELATED STORIES:
Fix for DNS software hole released
January 29, 2001
Cause of massive Net redirection still unclear
January 25, 2001
DNS security upgrade promises a safer Net
October 17, 2000

RELATED IDG.net STORIES:
Survey: 25% of Fortune 1000 has bad DNS
(InfoWorld.com)
Internet security hole called most serious yet
(Computerworld)
DNS software hole allows Web attacks
(IDG.net)
How to avoid Microsoft's DNS crisis
(InfoWorld.com)
Fix for DNS software hole released
(InfoWorld.com)
Microsoft Web site outages highlight DNS as single point of failure
(InfoWorld.com)
Microsoft's DNS eggs all in one basket
(Network World Fusion)
NSI tests multilingual DNS
(IDG.net)

RELATED SITES:
ISC
Men and Mice


Note: Pages will open in a new browser window
External sites are not endorsed by CNN Interactive.


 Search   





MARKETS
4:30pm ET, 4/16
144.70
8257.60
3.71
1394.72
10.90
879.91
 













Back to the top