Timeline: Kaminsky’s DNS vulnerability
Is the internet fatally flawed? IT PRO looks at how isolated attacks on Domain Name System servers have risen in profile to become one of the most talked about threats in 2008.

A vulnerability affecting the internet Domain Name System (DNS) discovered by Dan Kaminsky became the most high profile security threat of 2008.
He saw that there was a fatal flaw affecting the DNS - which translates web addresses to IP addresses. Users could be sent to malicious sites even if they typed in legitimate addresses and the potential for system-wide problems resulted in an unprecedented multi-vendor effort to create patches for the problem.
But DNS attacks are nothing new. The DNS looks to have problems which still haven't been fully solved, and we trace how the issue has progressed from isolated attacks to the story dominating security for the past couple of months.
February 2007: Hackers take aim at internet root serversAn attack was made on the DNS servers of three of the 13 computers that manage traffic on the internet in a 12-hour Denial of Service (DoS) attack. It was thought to be the one of the biggest seen in four years.
April 2007: New bug hits Windows DNS serviceVulnerability found in the Windows 2003 server which could allow hackers to take over servers and run remote code.
November 2007: DNS servers still vulnerableA study claims that although DNS servers are increasing and modernising, they are still vulnerable to attacks.
July 2008: DNS protection not good enoughDan Kaminsky claims that researchers are not providing enough protection for the DNS security hole which he discovered. Kaminsky's approach was different in that the fact it could speed up attacks and was more potent than seen previously. Kaminsky kept quiet about the flaw for six months, allowing a multi-vendor patch effort involving Microsoft, Sun and Cisco.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
July 2008: DNS attacks 'imminent' warns MicrosoftMicrosoft warns that the publication of exploit code has increased the chance of attack.
August 2008: Apple's patch fails to fully protect against DNS flawApple's belated attempt to create a patch for the DNS system problem does not completely solve the problem, say experts.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
Cisco polishes its platform but the network is still king
Analysis Cisco still believes its integrated platform will drive new value for customers, but its historic strength in networking is where it will have the edge in the AI era
By Solomon Klappholz Published
-
‘Divorced from reality’: HPE slams DOJ over bid to block Juniper deal, claims move will benefit Cisco
News HPE has criticized the US Department of Justice's attempt to block its acquisition of Juniper Networks, claiming it will benefit competitors such as Cisco.
By Nicole Kobie Published
-
Cisco wants to capitalize on the ‘DeepSeek effect’
News DeepSeek has had a seismic impact, and Cisco thinks it has strengths to help businesses transition to AI-native infrastructure
By Solomon Klappholz Published
-
Cisco Live EMEA 2025: All the news and updates as they happen
Live Blog Stay up to date with the latest information live from Amsterdam at Cisco’s annual EMEA conference
By Solomon Klappholz Last updated
-
How embracing flash storage helped Mississippi’s tax authority boost critical apps
Case study By ditching legacy systems and switching to flash storage, Mississippi’s Department of Revenue improved its backup strategy and cut restore times by more than a day
By Steve Ranger Published
-
The US just expanded funding for 5G Open RAN in a bid to help telecoms firms crack Huawei dominance
News The funding for 5G Open RAN aims to help US companies get a bigger slice of the network infrastructure market – and challenge Huawei’s dominance
By Steve Ranger Published
-
Cisco wants customers to ramp up AI adoption, so it’s partnering with Nvidia to bridge infrastructure hurdles
News Cisco has announced a new partnership with Nvidia to offer enterprises integrated, secure, and scalable data center solutions in a bid to drive AI adoption
By Solomon Klappholz Published
-
Cisco Live 2024: All the updates and announcements as they happen
Live Blog Stay up-to-date with the latest news and announcements from Cisco Live 2024 in Amsterdam
By Solomon Klappholz Last updated