republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » US Cable Support » Comcast » Comcast HSI » [DNS] Comcast and the DNS Server flaw issue
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[Speed] Comcast Statement on FCC Internet Regulation Decision »
« [Connectivity] modem activation problems  
AuthorAll Replies


Comcast_DNS

@aol.com

reply to jlivingood
Re: [DNS] Comcast and the DNS Server flaw issue

said by jlivingood See Profile :

The Comcast DNS servers were patched in advance of the CERT advisory. Some of the test tools may have limitations that do not show all of the possible protections. The NAT issue you see may be because you are behind a NAT box.
Certainly the Comcast DNS servers have been patched (and kudos to them for doing so), but perhaps the infrastructure they are behind is limiting the effectiveness.

I just hijacked borrowed a neighbor's WRT54G/Comcast connection, and I got these results:
Your name server, at 68.87.68.165, may be safe, but the NAT/Firewall in front of it appears to be interfering with its port selection policy. The difference between largest port and smallest port was only 297.
Please talk to your firewall or gateway vendor -- all are working on patches, mitigations, and workarounds.

------------------------------------------
Requests seen for 3fb39d027c49.toorrr.com:
68.87.68.165:16992 TXID=62773
68.87.68.165:16929 TXID=3653
68.87.68.165:17226 TXID=4680
68.87.68.165:16972 TXID=28772
68.87.68.165:17178 TXID=669
After temporarily changing the DNS to point to Level3's AnyCast servers, I got these results (nice to see that Level3 has updated):
Your name server, at 209.244.5.159, appears to be safe, but make sure the ports listed below aren't following an obvious pattern.
------------------------------------------
Requests seen for c1a7d2cdc9d8.toorrr.com:
209.244.5.159:50422 TXID=20587
209.244.5.159:43684 TXID=36013
209.244.5.159:44105 TXID=38976
209.244.5.159:42347 TXID=31019
209.244.5.159:41916 TXID=1615
Here is an example with OpenDNS, but still using the Linksys NAT router.
Your name server, at 208.69.32.13, appears to be safe, but make sure the ports listed below aren't following an obvious pattern.
------------------------------------------
Requests seen for b74008fa640a.toorrr.com:
208.69.32.13:31506 TXID=29292
208.69.32.13:10035 TXID=41242
208.69.32.13:23535 TXID=46244
208.69.32.13:40148 TXID=29386
208.69.32.13:39546 TXID=26965
One of these things is not like the other, can you tell which one?
-
Forums » US Cable Support » Comcast » Comcast HSI[Speed] Comcast Statement on FCC Internet Regulation Decision »
« [Connectivity] modem activation problems  


Sunday, 29-Nov 04:30:34 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [122] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [80] TiVo Sees Record Customer Losses
· [73] Weekend Open Thread
· [72] Verizon CEO: Hulu Will Be Dead Soon
· [69] In-Flight Internet Headed For Bumpy Landing?
· [62] Thanksgiving Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· [Newsgroups] Newzleech down? [Filesharing Software]
· So where do we level weapon skill now? [World of Warcraft]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· [ PVP] How to Make Discipline Priest so hard to kill? [World of Warcraft]
· Blue Ray: Samsung BD-P3600 or LG BD390 [Audio/Video Chat]
· [ Classes] DK best DPS spec [World of Warcraft]
· A very werid downloading problem! [AT&T West]