Showing posts with label security vendors. Show all posts
Showing posts with label security vendors. Show all posts

Wednesday, February 28, 2007

Hackers Hit Domain Name Servers

PC Virus Doctors' Dallas PC Repair report that hackers overnight targeted 3 of 13 root name servers that direct traffic for domain names. The top level domain targeted was ".org". The 12 hour attack came overnight and although the origins of the attacks was cloaked it appears it was coming from South Korea, according to Security News Portal. The power attack left computer experts rushing to pull the plug on the hackers as they flooded the information highway with their hack attack. A similar attack occurred in 2002 where scientists have since been able to find ways to divert the large volume of data the hackers threw at the servers. An interesting note, the root servers are operated by the U.S. Defense Department.

It really appears this could be easier dealt with like a physical firewall that would just cutoff an offending hacker, however, it has yet to be seen. The scare should prompt a security review and possible solution.

Vendors and Security Researchers Confrontation

Security vendors and researchers got into a confrontation over Black Hat's convention yesterday, according to Information Week. The issue was over proximity cards. The vendors felt as though such a revelation over its technology being exposed would allow duplication of their proximity cards that could allow unauthorized access into facilities. The security card vendor, HID Global Corps., voiced concerns that their intellectual property along with their patents would be exposed and the badges would no longer have the secure identification that was needed for sensitive physical areas. IOActive, the security researchers, reluctantly agreed to back off and not present their findings to the convention.

Here is the problem PC Virus Doctors see in this mess, that regardless if the findings were presented or not, HID Global Corp.s protective security devices were compromised and the end result is their product has lost any security value, monetary value and now noone should want to buy the flawed device. Why would they?