Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: US-CERT Vulnerability Note VU#800113



This is pretty rich:

Server Admin 10.5 Help

DNS Spoofing

DNS spoofing is adding false data to the DNS Server’s cache. This enables hackers to:

    * Redirect real domain name queries to alternative IP addresses.

For example, a falsified A record for a bank could point a computer user’s browser to a different IP address that is controlled by the hacker. A duplicate website could fool users into giving their bank account numbers and passwords to the hacker.

Also, a falsified mail record could enable a hacker to intercept mail sent to or from a domain. If the hacker then forward that mail to the correct mail server after copying the mail, this can go undetected.

    * Prevent proper domain name resolution and access to the Internet.

This is the most benign of DNS spoof attacks. It merely makes a DNS server appear to be malfunctioning.

The most effective method to guard against these attacks is vigilance. This includes maintaining up-to-date software and auditing DNS records regularly.

If exploits are found in the current version of BIND, the exploits are patched and a security update is made available for Mac OS X Server. Apply all such security patches. Regular audits of your DNS records can help prevent these attacks.

http://docs.info.apple.com/article.html?path=ServerAdmin/10.5/en/c3ns32.html _______________________________________________
Do not post admin requests to the list. They will be ignored.
Macos-x-server mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:
http://lists.apple.com/mailman/options/macos-x-server/email@hidden

This email sent to email@hidden
References: 
 >Re: US-CERT Vulnerability Note VU#800113 (From: "John C. Welch" <email@hidden>)
 >Re: US-CERT Vulnerability Note VU#800113 (From: Jaime Magiera <email@hidden>)
 >Re: US-CERT Vulnerability Note VU#800113 (From: Angus Fox <email@hidden>)
 >Re: US-CERT Vulnerability Note VU#800113 (From: Jose Hales-Garcia <email@hidden>)
 >Re: US-CERT Vulnerability Note VU#800113 (From: "Chris Barker" <email@hidden>)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.