Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Multiple Vendors Tackle DNS Design Flaw » Quick Responses - Teksavvy
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
« DNS Changes affecting SW Firewalls  
AuthorAll Replies


shopkins

join:2008-05-23
Nepean, ON
·TekSavvy Solutions..
·Bell Sympatico

reply to TKJunkMail
Re: Quick Responses - Teksavvy

said by TKJunkMail See Profile :

Better that the problem was avoided all together like the OpenDNS service did. If you used OpenDNS for your DNS servers you never were exposed at all.

More info on this security issue here in the BBR Security forum: »Internet flaw could let hackers take over the Web
True - apparently the potential exploit of the flaw has been known for a while (recall reading a comment that the DNS system has been known to be broken for a while). OpenDNS is a good solution for someone with some knowledge but I am pretty sure that the big ISP's (Bell, Telus & Rogers in Canada) would not pre-configure their service to use someone else's DNS. And 99% of internet users would never even want to fiddle with those setting... unlike those of us here on DSLR that have a higher comfort level with these changes.

Unsure exactly what TekSavvy did to patch their system but I would guess (since they said that they are not on an MS system) that they upgraded their BIND from v8 to v9. But that is pure speculation because I can honestly say that I do not know what that last sentence implies wrt ease of an upgrade


sporkme
drop the crantini and move it, sister
Premium,MVM
join:2000-07-01
Morristown, NJ
·Optimum Online

said by shopkins See Profile :

True - apparently the potential exploit of the flaw has been known for a while (recall reading a comment that the DNS system has been known to be broken for a while).
Sometimes the nutjobs are 100% right:

»cr.yp.to/djbdns/forgery-cost.txt
-
Forums » Multiple Vendors Tackle DNS Design Flaw« DNS Changes affecting SW Firewalls  


Wednesday, 02-Dec 16:07:10 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [159] Comcast Releasing Promised Usage Meter
· [83] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [77] Latest Consumer Reports Survey Not Kind To AT&T
· [69] Baltimore To Ban Lazy Cable Installs
· [60] Broadband Killed The Game Console
· [54] Rogers Unveils The ISP Dream Model
· [46] ACTA: Global Three Strikes
· [41] Rural Carriers Quickly Embracing Fiber
· [38] Charter Exits Chapter 11
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
Most people now reading
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Quality/longevity of 15A 120V receptacles [Home Repair & Improvement]
· A little freaky, not sure if its legit. [Spam, Scam and Phishbusters]
· MS admits Windows Updates principally created to annoy [Security]
· UBB round 2 at the CRTC [Canadian Broadband]
· Am I the only one that loves to work in IT? [No, I Will Not Fix Your #@$!! Computer]
· Using AirMax to provide triple play services? [Wireless Service Providers]
· So I found a gold mine... [World of Warcraft]
· DK Weapon Upgrade [World of Warcraft]
· [Business] how to bridge a smc 8014 business class modem [Comcast HSI]