Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » O Canada! » Canadian » Rogers » Rogers DNS still vulnerable?
Search Topic:
Uniqs:
635
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Rogers Still Throttling P2P? »
« SW download Successful - Via NMS  
AuthorAll Replies


gabtris

join:2007-02-08
Kanata, ON

 Rogers DNS still vulnerable?

I had to go over to my father's house today and set him up onto the OpenDNS servers simply because the Rogers DNS server (and yes, its the one that was getting auto-configured) was showing the following:

All requests came from the following source port: 50776

Due to events outside our control, details of the vulnerability have been leaked. Please consider using a safe DNS server, such as OpenDNS. Note: Comcast users should not worry.
--------------------------------------------------------------------------------
Requests seen for 73dbf747dd4e.doxdns5.com:
64.71.246.222:50776 TXID=29975
64.71.246.222:50776 TXID=39970
64.71.246.222:50776 TXID=52783
64.71.246.222:50776 TXID=8807
64.71.246.222:50776 TXID=44011

I can't believe that Rogers has not done anything about this since they should have known about the problem for a month now. Hopefully someone here that knows a bit more about Rogers and its service can enlighten me or point out an admin that can be notified.

While it is nice that the Rogers DNS server was not sending all queries out of port 53, its just as bad to send them out of any single port.

Thanks in advance


anon242342

@rogers.com

They already know about it. But you have to know the Rogers management structure to understand why it takes so long to get anything done.

For a small agile company it's a quick fix, for a big dinosaur like Rogers expect multiple levels of approvals and testing and more approvals before anything gets done.



gabtris

join:2007-02-08
Kanata, ON
Well... Given the number of service providers that have already patched their systems and how much larger they are (eg. Comcast), Rogers performance is absolutely pathetic if they haven't patched everything up yet.


name untaken

@rogers.com
reply to gabtris
Its really not something to get worried about, people are way overreacting here, the ods of someone exploiting the vulnerablity is 1 out of 65534 x number of DNS servers they run. My guestimate would be around 20 servers.


gabtris

join:2007-02-08
Kanata, ON

reply to gabtris
If I were you I would go and read up about the presentation that Dan Kaminsky gave at Black Hat last week and THEN tell me it's nothing to get worried about. And I don't believe the number of DNS servers they run has anything to do with it as you only need to poison the cache on 1 server in order to see returns on your hacking.

And 1 in 65534 is not something I want to take a chance with since the avg hacker can send 65534 packets in a very short amount of time...
-
Forums » O Canada! » Canadian » RogersRogers Still Throttling P2P? »
« SW download Successful - Via NMS  


Wednesday, 02-Dec 20:45:28 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [161] Comcast Releasing Promised Usage Meter
· [93] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [79] Latest Consumer Reports Survey Not Kind To AT&T
· [70] Baltimore To Ban Lazy Cable Installs
· [62] Broadband Killed The Game Console
· [54] Rogers Unveils The ISP Dream Model
· [46] ACTA: Global Three Strikes
· [41] Rural Carriers Quickly Embracing Fiber
· [38] Charter Exits Chapter 11
· [38] AT&T, Verizon Drop 3G Ad Dispute
Most people now reading
· False positive in Avast! or is it real? [Security]
· MS admits Windows Updates principally created to annoy [Security]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Quality/longevity of 15A 120V receptacles [Home Repair & Improvement]
· 16% packet loss. damn dsl. los angeles [AT&T West]
· Ooma changing features [VOIP Tech Chat]
· [WIN7] When exactly should you flash bios when installing new OS [Microsoft Help]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Am I the only one that loves to work in IT? [No, I Will Not Fix Your #@$!! Computer]
· Using AirMax to provide triple play services? [Wireless Service Providers]