On CBS MoneyWatch: 6 big myths about gas mileage
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 4 of 4:
« Previous
An example
The error is the way the proxy caches dns entries. If I
can entice you (or any of the users using the same proxy)
to visit my site (web link, html email, virii), or I have taken
control of another site's dns server I can return a reverse
dns value for a domain I'm not authoritative over (eg your
bank).

The Proxy Server will then use this polluted dns value for its
forward dns lookup, so when your employees go to do your
banking they'll go to my site.

The only limiting factor for this is I must be the first reverse
lookup result (for it to be cached)!

But given the amount of information I could extract from
your employees, all without their knowledge or indeed your
IT dept, I'd think this is a little more serious than
"important".
Posted by: Richard Flude   Posted on: 11/10/04 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Windows 3.0 has a bug in it too  mojoman_x@... | 11/09/04
And I thought this was serious  Richard Flude | 11/09/04
Did it really say that?  johnwsaundersiii@... | 11/10/04
An example  Richard Flude | 11/10/04

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

Meet Doc