Internet service providers that serve advertising when a user requests a Web page that doesn’t exist are exposing their users to a giant security breach, according to security researcher Dan Kaminsky. The vulnerability resulting from the practice, which is an increasingly common way for ISPs to make money from users’ typos, was identified last week on Earthlink by Kaminsky, who is director of penetration testing for security firm IOActive. Kaminsky presented his findings at the Toorcon hacker conference on Saturday.
Expert: Domain Name Redirects Open Door for Hackers
Posted by: Katherine Noyes April 21, 2008 02:47 PMInternet service providers that serve advertising when a user requests a Web page that doesn’t exist are exposing their users to a giant security breach, according to security researcher Dan Kaminsky. The vulnerability resulting from the practice, which is an increasingly common way for ISPs to make money from users’ typos, was identified last week on Earthlink by Kaminsky, who is director of penetration testing for security firm IOActive. Kaminsky presented his findings at the Toorcon hacker conference on Saturday.