Newsletters

Select newsletters below and click the button to sign up!

Boston News NY News
DC News Internet Daily
SiliconValley News
InternetNews Business Report




Become a Marketplace Partner



Partner With Us















Internetnews Bloggers

Recent Entries

Archives

April 2009
Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30    

Monthly Archives

Search The Blog

Netstat -vat by Sean Michael Kerner (bio)

A command line view of IT



Apple finally patches Kaminsky DNS flaw

blackhat.jpg
From the "better late than never" files:

For some unknown reason, Apple did not have a patch available for the DNS flaw that Dan Kaminsky first announced more than two weeks ago, despite the fact that one was available for BIND (which is what Apple uses). Apple has finally gotten off its iPhone rich tail and now put out an official patch, saving users from a flaw that has been weaponized and exploited in the wild.

The BIND update is part of Apple security update 2008-005 which also includes fixes for PHP, OpenLDAP and OpenSSL.

Do you see a pattern here? Cause I sure do.

Apple uses a lot of open source software and that's great. Apple also doesn't seem to be offering its users the updated packages for some of those open source packages as quickly as they are actually available in the general community (not so great).

It sure would be easy pickings for hacker to just look at the open source apps running on a Mac, see what isn't update and then go after vulnerabilities that have already been publicly exposed.

| Comments (1) | TrackBacks (0) | Share

0 TrackBacks

Listed below are links to blogs that reference this entry: Apple finally patches Kaminsky DNS flaw.

TrackBack URL for this entry: https://swarm.jupitermedia.com/mt-tb.cgi/4173

1 Comments

64.4.71.56 said:

No surprise here. This is to be expected from Apple.

This latest update fixed about 17 known vulnerabilities and the one from the previous month fixed about 20. At least the frequency of their security updates has improved.

So what if they didn't release a patch right away for the BIND vulnerability -- I don't suspect there to be many Mac-based DNS servers on the internet. The important vendors released their patches in a timely manner, and that is what counts.

I mean, I don't know the background behind the disclosure of this vulnerability, but maybe Kaminsky, CERT, or whomever should have coordinated the disclosure differently.

Leave a comment