A browser technology that binds single IP addresses to DNS names causes a vulnerability that will especially affect Web2.0 applications. Ironically, this techniqie (DNS pinning) has been developed to protect users from DNS spoofing, but the various embedded technologies within a browser might do their own DNS handling and circumvent the browser's security mechanisms. This way malicious web sites might establish a VPN connection to the victim's network. There's no patch yet to solve this issue that could be called a design flaw. Especially web sites and services that need a lot of JavaScript or various browser plugins to run will be affected by this challenge. Looks like big fun for Web2.0 sites. (Source)
« On High Species Density | Main | On Amended Standards Policy »
On Web2.0 Joys To Come
TrackBack
TrackBack URL for this entry:
http://www.mabuse.de/cgi-bin/MT/mt-tb.cgi/120