Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » With DNS Flaw Now Public, Attack Code Imminent
Search Topic:
Uniqs:
2362
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
thanx »
« Sunbelt Vipre Now Available  
page: 1 · 2
AuthorAll Replies
-

SUMware
Premium
join:2002-05-21

reply to Imagine Reason
Re: DNS Randomness Tests

»www.opendns.com/how/free/how-can···be-free/
OpenDNS makes money the same way Google and Yahoo do — by showing relevant ads when we show you search results.

This can be added this to the 'hosts' file: 127.0.0.1 guide.opendns.com


Imagine Reason

@rr.com
reply to TKJunkMail
My statement stands.


TKJunkMail
Enjoy the sun
Premium
join:2002-03-03
Avalon, NJ
·Sprint Mobile Broa..
·Comcast

reply to Imagine Reason
said by Imagine Reason :

OpenDNS is a private company and not open source as its name may imply. They also hijack location bar searches. Just so everyone knows.
That can be easily turned off:
»Re: rogers inserting advertisements into my browser - WTF?
--
My BLOG .. .. Internet News .. .. My Web Page
Ask yourself one question: 'Do I feel lucky?' Well, do ya punk?


Imagine Reason

@rr.com
 reply to Libra
OpenDNS is a private company and not open source as its name may imply. They also hijack location bar searches. Just so everyone knows.

Libra
Premium
join:2003-08-06
USA
reply to SipSizzurp
Thank you, SipSizurp, for posting the pictures for me. In another thread I found out I could put those openDNS numbers into my Westell modem, so I did that instead and it covered both computer.

Sincerely, Libra

SUMware
Premium
join:2002-05-21

reply to Sparrow
said by Sparrow See Profile :

One can open an account
OpenDNS states that creating an account is purely optional and completely unnecessary to use their service.

SipSizzurp
Fo' Shizzle
Premium
join:2005-12-28
Hilo, HI
·RoadRunner Cable

reply to Sparrow
said by Sparrow See Profile :

...open an account, download the updater...

--
I spent most of my money on Women and Beer, and the rest I just wasted !


Sparrow
Crystal Sky
Premium
join:2002-12-03
Sachakhand

reply to SipSizzurp
SipSizzurp See Profile,

It's much easier to use the OpenDNS page. It guides a client through with implicit and easy directions. One can open an account, download the updater and you are on your way.

There is also a forum for support questions.

SipSizzurp
Fo' Shizzle
Premium
join:2005-12-28
Hilo, HI
·RoadRunner Cable


1 edit
reply to Libra
Click for full size
said by Libra See Profile :

... after I inserted the two dns numbers and clicked "okay" I got this message "In order to use DNS you must specify a host name for your computer."
If that is your Win98 machine, then the host name will be fine with anything you enter. For the XP box see the screen shot.
--
I spent most of my money on Women and Beer, and the rest I just wasted !

Libra
Premium
join:2003-08-06
USA

reply to TheWiseGuy
Hi WiseGuy,
Thank you for your instructions. However, I ran into a problem: after I inserted the two dns numbers and clicked "okay" I got this message "In order to use DNS you must specify a host name for your computer." I didn't know what to put in, so I canceled it.

I'm also wondering what I have to do for the XP computer.

Thank you.

Sincerely, Libra


FiOS Dan
Premium
join:2001-07-06
Redondo Beach, CA
·Verizon FIOS

 reply to FiOS Dan
Re: With DNS Flaw Now Public, Attack Code Imminent

Click for full size
Thank you OpenDNS!

TheWiseGuy
Dog And Butterfly
Premium,MVM
join:2002-07-04
Yonkers, NY

reply to jbob
Re: Good test to check your ISPs DNS servers

said by jbob See Profile :

FYI The OARC test may not be as accurate on Comcast. See this thread:
»[DNS] Comcast and the DNS Server flaw issue

Even Dan Kaminsky has chimed in.
It seems both tests can give different results at times, especially if the servers source ports are not completely random. Have gotten results from Poor to Great with the new test. In looking at the ports used, it looks as if they tend to be in one range and then change to another range for my ISP.
--
Warning, If you post nonsense and use misinformation and are here to argue based on those methods, you will be put on ignore.


TKJunkMail
Enjoy the sun
Premium
join:2002-03-03
Avalon, NJ
·Sprint Mobile Broa..
·Comcast

reply to jbob
said by jbob See Profile :

FYI The OARC test may not be as accurate on Comcast. See this thread:
»[DNS] Comcast and the DNS Server flaw issue

Even Dan Kaminsky has chimed in.
Thanks for update. I did try the doxpara test too. But the doxpara test only tests the 1st DNS server it finds in the DNS list for the computer. The entropy test tests all the entries in the computers DNS list. So that made it easier to use.

In any case, the opendns servers test as well as or better than Comcasts and I'll stick with them.
--
My BLOG .. .. Internet News .. .. My Web Page
Ask yourself one question: 'Do I feel lucky?' Well, do ya punk?


jbob
Reach Out and Touch Someone
Premium
join:2004-04-26
Little Rock, AR
reply to TKJunkMail
FYI The OARC test may not be as accurate on Comcast. See this thread:
»[DNS] Comcast and the DNS Server flaw issue

Even Dan Kaminsky has chimed in.


TKJunkMail
Enjoy the sun
Premium
join:2002-03-03
Avalon, NJ
·Sprint Mobile Broa..
·Comcast


1 edit
 reply to JohnInSJ
said by JohnInSJ See Profile :

OpenDNS, and just about every other DNS has been patched already. This was more a media event then anything else.
If you want to check whether your ISPs DNS servers are updated, you can run this test.

»entropy.dns-oarc.net/test/

It tests for BOTH port randomness and Transaction ID randomness.

I use Opendns and they showed GREAT on both tests. But my ISPs DNS(Comcast) that I use as the 3rd DNS entry in my list showed as POOR on the port randomness test.
--
My BLOG .. .. Internet News .. .. My Web Page
Ask yourself one question: 'Do I feel lucky?' Well, do ya punk?


TKJunkMail
Enjoy the sun
Premium
join:2002-03-03
Avalon, NJ
·Sprint Mobile Broa..
·Comcast

reply to FiOS Dan
Re: With DNS Flaw Now Public, Attack Code Imminent

said by FiOS Dan See Profile :

"One day after a security company accidentally posted details of a serious flaw in the Internet's Domain Name System (DNS), hackers are saying that software that exploits this flaw is sure to pop up soon." (More...).
I would question whether that release was accidental. Seems more like it was done on purpose because they were annoyed that they weren't given all the info and part of the "in-crowd" that Kaminsky gave the info to.
--
My BLOG .. .. Internet News .. .. My Web Page
Ask yourself one question: 'Do I feel lucky?' Well, do ya punk?

TheWiseGuy
Dog And Butterfly
Premium,MVM
join:2002-07-04
Yonkers, NY

reply to Libra
Re: DNS Randomness Tests

To switch to opendns follow the instructions in Section 4 of the link below (instructions quoted) for windows 98 and use the following IP addresses for DNS servers, (ignore the Domain instructions and the gateway instructions.)

208.67.222.222
208.67.220.220

»Satellite Forum FAQ »[DW4000] I'm sharing my connection on a LAN. Do I need to do more?

said by faq :

Windows 98:

Start => Settings => Control Panel => click on the Network icon or right-click on the Network Neighborhood icon and choose 'Properties'. Either way gets you into the Network configuration screens.
From the list of installed clients, protocols and services, locate TCP/IP bound to the NIC It will look something like this: TCP/IP -> your network card. The arrow indicates the protocol is bound to that adapter. Highlight that and then click the Properties button. This gets you into the TCP/IP configuration screens. Click the DNS Configuration tab. Put as dot in the 'Enable DNS' radio button.
Then add the DNS servers,

--
Warning, If you post nonsense and use misinformation and are here to argue based on those methods, you will be put on ignore.

Libra
Premium
join:2003-08-06
USA

reply to SUMware
I did this test twice on my 98se computer and got this:

1. 68.237.161.37 appears to have POOR source port randomness and GREAT transaction ID randomness.
2. 68.237.161.38 appears to have POOR source port randomness and GREAT transaction ID randomness.

The first time I did this test the results were the same but the number was 68.237.161.36.

I also did the test on our XP computer which has the MS Patch, and AOL running - AOL came up great for both tests, but my dsl numbers (similar to above) had the same poor source port and great randomness.

I have Verizon DSL with the Westell 2200 modem (that has a NAT Firewall router) and I use a switch to connect both pcs.

When Dan Kaminsky first had his test both computers tested "your dns server appears safe". After he changed the test, both computers show "your NAT is interfering".

I don't understand all of this. How do I fix this (or does Verizon have to fix this)? Also, I don't know how to switch to an open DNS.

Thank you.

Sincerely, Libra


caffeinator
Coming soon to a cup near you..
Premium
join:2005-01-16
Spokane, WA
·WebBand

reply to SUMware
Nice one..the other test never did work on my machine.
However, using my primary DNS server from the ISP I get:

Source Port Randomness: POOR (one port used but it's a high range)
Transaction ID Randomness: GREAT (25 diff. ID's used)

So, is that a problem?
I use openDNS as my secondary as a failsafe FWIW.

-CaFF

TheWiseGuy
Dog And Butterfly
Premium,MVM
join:2002-07-04
Yonkers, NY

reply to SUMware
Re: With DNS Flaw Now Public, Attack Code Imminent

Thanks for the link.

OOL seems to have just patched, the link indicated they had done it right, versus dox which indicated possible NAT. Looks as if they use a larger sample.
--
Warning, If you post nonsense and use misinformation and are here to argue based on those methods, you will be put on ignore.
Forums » Up and Running » Security » Securitythanx »
« Sunbelt Vipre Now Available  
page: 1 · 2


Wednesday, 02-Dec 15:32:19 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [159] Comcast Releasing Promised Usage Meter
· [79] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [77] Latest Consumer Reports Survey Not Kind To AT&T
· [69] Baltimore To Ban Lazy Cable Installs
· [60] Broadband Killed The Game Console
· [54] Rogers Unveils The ISP Dream Model
· [46] ACTA: Global Three Strikes
· [41] Rural Carriers Quickly Embracing Fiber
· [38] Charter Exits Chapter 11
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
Most people now reading
· A little freaky, not sure if its legit. [Spam, Scam and Phishbusters]
· MS admits Windows Updates principally created to annoy [Security]
· Am I the only one that loves to work in IT? [No, I Will Not Fix Your #@$!! Computer]
· UBB round 2 at the CRTC [Canadian Broadband]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Windows 7 boot manager editing questions [Microsoft Help]
· LFM Overkill [World of Warcraft]
· DK Weapon Upgrade [World of Warcraft]
· Using AirMax to provide triple play services? [Wireless Service Providers]
· Maximizing Rogue DPS for 3.1 [World of Warcraft]