site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
AuthorAll Replies


FiOS Dan
Premium
join:2001-07-06
Redondo Beach, CA

reply to NetFixer

Re: Exploit code for Kaminsky DNS Bug Goes Wild

Thanks for the reply NetFixer. What I was referring to is the case where a road warrior's internet access is via a hotel or airport WiFi whose router DNS settings would override his or her laptop's. Is this not the case?
--
Courage is being scared to death but saddling up anyway.


NetFixer
Freedom is NOT free
Premium
join:2004-06-24
The 'Boro
Reviews:
·Vonage
·Cingular Wireless
·Comcast
·AT&T Southeast

3 edits

said by FiOS Dan:

Thanks for the reply NetFixer. What I was referring to is the case where a road warrior's internet access is via a hotel or airport WiFi whose router DNS settings would override his or her laptop's. Is this not the case?
No, If you manually enter the DNS servers in the TCPIP properties for the WiFi card, that is what will be used. I showed a picture of my desktop PC's NIC, but the same setup and principle would apply for a WiFi card. Here are sample ipconfig /all and nslookup www.yahoo.com commands for several different scenarios that I just made from a foreign WiFi connection to illustrate my point:




This is using the default settings for a foreign WiFi connection:
(in this case it is safe because Comcast has updated their DNS, but of course, that would not always be the case)

C:\>ipconfig /all


Windows IP Configuration

Host Name . . . . . . . . . . . . : RWS-6325
Primary Dns Suffix . . . . . . . : dcs-net.net
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : dcs-net
dcs-net.net

Ethernet adapter Local Area Connection 2:

Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : Bluetooth PAN Network Adapter
Physical Address. . . . . . . . . : 00-11-E0-02-F6-D6

Ethernet adapter Local Area Connection:

Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : Broadcom NetLink (TM) Gigabit Ethernet
Physical Address. . . . . . . . . : 00-17-A4-E3-E7-CF

Ethernet adapter Wireless Network Connection:

Connection-specific DNS Suffix . : hsd1.tn.comcast.net.
Description . . . . . . . . . . . : Broadcom 802.11b/g WLAN
Physical Address. . . . . . . . . : 00-1A-73-67-2C-DC
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.1.104
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 68.87.68.162
68.87.74.162
68.87.64.196
Lease Obtained. . . . . . . . . . : Friday, July 25, 2008 10:31:56
Lease Expires . . . . . . . . . . : Saturday, July 26, 2008 10:31:56


C:\>nslookup www.yahoo.com
Server: cns.s3woodstock.ga.atlanta.comcast.net
Address: 68.87.68.162

Non-authoritative answer:
Name: www.yahoo-ht3.akadns.net
Address: 69.147.76.15
Aliases: www.yahoo.com

*** You will note that in this case the WiFi connection's DNS was used. ***




This is using a manually entered known good set of public DNS servers:

C:\>ipconfig /all


Windows IP Configuration

Host Name . . . . . . . . . . . . : RWS-6325
Primary Dns Suffix . . . . . . . : dcs-net.net
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : dcs-net
dcs-net.net

Ethernet adapter Local Area Connection 2:

Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : Bluetooth PAN Network Adapter
Physical Address. . . . . . . . . : 00-11-E0-02-F6-D6

Ethernet adapter Local Area Connection:

Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : Broadcom NetLink (TM) Gigabit Ethernet
Physical Address. . . . . . . . . : 00-17-A4-E3-E7-CF

Ethernet adapter Wireless Network Connection:

Connection-specific DNS Suffix . : hsd1.tn.comcast.net.
Description . . . . . . . . . . . : Broadcom 802.11b/g WLAN
Physical Address. . . . . . . . . : 00-1A-73-67-2C-DC
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.1.104
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 4.2.2.4
4.2.2.6
Lease Obtained. . . . . . . . . . : Friday, July 25, 2008 10:39:15
Lease Expires . . . . . . . . . . : Saturday, July 26, 2008 10:39:15


C:\>nslookup www.yahoo.com
Server: vnsc-pri-dsl.genuity.net
Address: 4.2.2.4

Non-authoritative answer:
Name: www.yahoo-ht3.akadns.net
Address: 69.147.76.15
Aliases: www.yahoo.com

*** You will note that in this case the manually entered public DNS was used. ***




This is using the manually entered company's publicly visible DNS servers:

C:\>ipconfig /all


Windows IP Configuration

Host Name . . . . . . . . . . . . : RWS-6325
Primary Dns Suffix . . . . . . . : dcs-net.net
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : dcs-net
dcs-net.net

Ethernet adapter Local Area Connection 2:

Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : Bluetooth PAN Network Adapter
Physical Address. . . . . . . . . : 00-11-E0-02-F6-D6

Ethernet adapter Local Area Connection:

Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : Broadcom NetLink (TM) Gigabit Ethernet
Physical Address. . . . . . . . . : 00-17-A4-E3-E7-CF

Ethernet adapter Wireless Network Connection:

Connection-specific DNS Suffix . : hsd1.tn.comcast.net.
Description . . . . . . . . . . . : Broadcom 802.11b/g WLAN
Physical Address. . . . . . . . . : 00-1A-73-67-2C-DC
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.1.104
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 66.134.0.234
74.245.184.227
Lease Obtained. . . . . . . . . . : Friday, July 25, 2008 11:11:09
Lease Expires . . . . . . . . . . : Saturday, July 26, 2008 11:11:09


C:\>nslookup www.yahoo.com
Server: dcs-net.net
Address: 66.134.0.234

Non-authoritative answer:
Name: www.yahoo-ht3.akadns.net
Address: 69.147.76.15
Aliases: www.yahoo.com

*** You will note that in this case the manually entered company DNS was used. ***




This is using a PPTP VPN connection to the company network:

C:\>ipconfig /all


Windows IP Configuration

Host Name . . . . . . . . . . . . : RWS-6325
Primary Dns Suffix . . . . . . . : dcs-net.net
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : dcs-net
dcs-net.net

Ethernet adapter Local Area Connection 2:

Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : Bluetooth PAN Network Adapter
Physical Address. . . . . . . . . : 00-11-E0-02-F6-D6

Ethernet adapter Local Area Connection:

Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : Broadcom NetLink (TM) Gigabit Ethernet
Physical Address. . . . . . . . . : 00-17-A4-E3-E7-CF

Ethernet adapter Wireless Network Connection:

Connection-specific DNS Suffix . : hsd1.tn.comcast.net.
Description . . . . . . . . . . . : Broadcom 802.11b/g WLAN
Physical Address. . . . . . . . . : 00-1A-73-67-2C-DC
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.1.104
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 68.87.68.162
68.87.74.162
68.87.64.196
Lease Obtained. . . . . . . . . . : Friday, July 25, 2008 10:46:58
Lease Expires . . . . . . . . . . : Saturday, July 26, 2008 10:46:58

PPP adapter DCS Enterprises:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : WAN (PPP/SLIP) Interface
Physical Address. . . . . . . . . : 00-53-45-00-00-00
Dhcp Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.10.201
Subnet Mask . . . . . . . . . . . : 255.255.255.255
Default Gateway . . . . . . . . . : 192.168.10.201
DNS Servers . . . . . . . . . . . : 192.168.10.1


C:\>nslookup www.yahoo.com
*** Can't find server name for address 68.87.68.162: Query refused
*** Can't find server name for address 68.87.74.162: Query refused
*** Can't find server name for address 68.87.64.196: Query refused
Server: dcs-gw1.dcs-net
Address: 192.168.10.1

Non-authoritative answer:
Name: www.yahoo-ht3.akadns.net
Address: 69.147.76.15
Aliases: www.yahoo.com

*** You will note that even though the notebook attempted to use the WiFi connection's DNS first, the company's firewall prevented access and used its own DNS. ***




This is using an IPSEC VPN connection to company network:

C:\>ipconfig /all


Windows IP Configuration

Host Name . . . . . . . . . . . . : RWS-6325
Primary Dns Suffix . . . . . . . : dcs-net.net
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : dcs-net
dcs-net.net

Ethernet adapter Local Area Connection 2:

Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : Bluetooth PAN Network Adapter
Physical Address. . . . . . . . . : 00-11-E0-02-F6-D6

Ethernet adapter Local Area Connection:

Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : Broadcom NetLink (TM) Gigabit Ethernet
Physical Address. . . . . . . . . : 00-17-A4-E3-E7-CF

Ethernet adapter Wireless Network Connection:

Connection-specific DNS Suffix . : hsd1.tn.comcast.net.
Description . . . . . . . . . . . : Broadcom 802.11b/g WLAN
Physical Address. . . . . . . . . : 00-1A-73-67-2C-DC
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.1.104
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.10.1
68.87.68.162
68.87.74.162
68.87.64.196
Lease Obtained. . . . . . . . . . : Friday, July 25, 2008 10:55:11
Lease Expires . . . . . . . . . . : Saturday, July 26, 2008 10:55:11


C:\>nslookup www.yahoo.com
Server: dcs-gw1.dcs-net
Address: 192.168.10.1

Non-authoritative answer:
Name: www.yahoo-ht3.akadns.net
Address: 69.147.76.15
Aliases: www.yahoo.com

*** You will note that in this case the company's DNS was used first, so the WiFi connection's DNS did not come into play. ***




There is almost always more than one way to accomplish the same task; in this case, ensuring a safe DNS source even when on the road.




As a control sample, this is what a WiFi connection to my office LAN looks like:

C:\>ipconfig /all


Windows IP Configuration

Host Name . . . . . . . . . . . . : RWS-6325
Primary Dns Suffix . . . . . . . : dcs-net.net
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : dcs-net
dcs-net.net

Ethernet adapter Local Area Connection 2:

Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : Bluetooth PAN Network Adapter
Physical Address. . . . . . . . . : 00-11-E0-02-F6-D6

Ethernet adapter Local Area Connection:

Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : Broadcom NetLink (TM) Gigabit Ethernet
Physical Address. . . . . . . . . : 00-17-A4-E3-E7-CF

Ethernet adapter Wireless Network Connection:

Connection-specific DNS Suffix . : dcs-net
Description . . . . . . . . . . . : Broadcom 802.11b/g WLAN
Physical Address. . . . . . . . . : 00-1A-73-67-2C-DC
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.10.68
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.10.1
DHCP Server . . . . . . . . . . . : 192.168.10.1
DNS Servers . . . . . . . . . . . : 192.168.10.2
192.168.10.1
Primary WINS Server . . . . . . . : 192.168.10.2
Lease Obtained. . . . . . . . . . : Friday, July 25, 2008 11:28:15
Lease Expires . . . . . . . . . . : Monday, July 28, 2008 11:28:15


C:\>nslookup www.yahoo.com
Server: dcs-srv.dcs-net.net
Address: 192.168.10.2

Non-authoritative answer:
Name: www.yahoo-ht3.akadns.net
Address: 69.147.76.15
Aliases: www.yahoo.com

--
We can never have enough of nature.
We need to wit ness our own limits transgressed, and some life pasturing freely where we never wander.Test your firewall.


FiOS Dan
Premium
join:2001-07-06
Redondo Beach, CA

Very informative NetFixer. I will manually enter the OpenDNS servers in my laptop's setting. Thanks a lot.
--
Courage is being scared to death but saddling up anyway.


Wednesday, 30-May 06:43:02 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics