Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » 1 In 10 DNS Servers Vulnerable To Cache Poisoning » OpeNDNS
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
« Drinking Milk Leads to Heroin Addiction, Too!  
AuthorAll Replies

jester121
Premium
join:2003-08-09
Lake Zurich, IL
·surpasshosting
·ViaTalk

reply to robl27
Re: OpeNDNS

Level 3 mentioned in passing (about the time the details on the cache poisoning proof of concept came out) that they would eventually be shutting off public access to their beloved and ubiquitous 4.2.2.x DNS servers.

That will be a very interesting day in the IT field, when we learn who's sloppy and who's not.

kieranmullen
Premium
join:2005-12-12
Portland, OR
clubs:
·Gizmo5
·Skype
·Vitelity VOIP
·magicjack.com
·Verizon FIOS
·Vonage
·ViaTalk
·VoicePulse

Is it considered sloppy to put clients on OpenDNS rather than their ISP's dns? I mean OpenDNS has so many other nice options as far as filtering goes as well and the ads are not a big turnoff.

said by jester121 See Profile :

Level 3 mentioned in passing (about the time the details on the cache poisoning proof of concept came out) that they would eventually be shutting off public access to their beloved and ubiquitous 4.2.2.x DNS servers.

That will be a very interesting day in the IT field, when we learn who's sloppy and who's not.


backfeed
is giving feedback

join:2002-12-16
Peru, IN
·Comcast Digital Vo..
·Comcast Formerly ..

reply to jester121
I am using Open DNS now on my networks, I have used Level 3's in a pinch, but I always thought that it was wrong to use them as a standard. They do work good, but I am really surprised that they have left them open to the public for so long...
--
There is 10 types of people. Those whom can read Binary and those who cannot.

jester121
Premium
join:2003-08-09
Lake Zurich, IL
·surpasshosting
·ViaTalk

reply to kieranmullen
No clue about that, we run our own internal DNS. The thing is that Level 3's 4.2.2.x servers aren't "officially" open to the public like OpenDNS ones are, they've just been around forever and easy to remember. I use them occasionally for troubleshooting or if I need to go to an ISP website to fix someone's computer...

kieranmullen
Premium
join:2005-12-12
Portland, OR
clubs:
·Gizmo5
·Skype
·Vitelity VOIP
·magicjack.com
·Verizon FIOS
·Vonage
·ViaTalk
·VoicePulse


2 edits
said by jester121 See Profile :

No clue about that, we run our own internal DNS. The thing is that Level 3's 4.2.2.x servers aren't "officially" open to the public like OpenDNS ones are, they've just been around forever and easy to remember. I use them occasionally for troubleshooting or if I need to go to an ISP website to fix someone's computer...
They are the servers that are used for Verizon Fios Setup too! I wonder if they have some sort of agreement with them. Simply typing DNS in the help section of Verizon.net did not yield any results except for a dial up dns server.


NetFixer
Freedom is NOT Free
Premium
join:2004-06-24
Murfreesboro, TN
·AT&T Southeast
·Vonage
·Cingular Wireless
·AT&T CallVantage


3 edits
said by kieranmullen See Profile :

They are the servers that are used for Verizon Fios Setup too! I wonder if they have some sort of agreement with them.
Ask and ye shall receive


The reason that the 4.2.2.x DNS servers are frequently referred to as Level3 servers is that the IP NetRange/CIDR is owned by Level3.

--
History does not long entrust the care of freedom to the weak or the timid.
-- Dwight D. Eisenhower
Test your firewall.
Smell the flowers.

kieranmullen
Premium
join:2005-12-12
Portland, OR
clubs:
·Gizmo5
·Skype
·Vitelity VOIP
·magicjack.com
·Verizon FIOS
·Vonage
·ViaTalk
·VoicePulse


1 edit
ask... well I suppose I could have looked it up as well.

Why would level3 have a hold on IP blocks from verizon? You would think that verizon would have many of its own blocks registered.

»www.isp-planet.com/news/2002/lvl···129.html

Level3 bought genuity.com which was the networking GTE I believe. Verizon bought GTE.

Nevermind its a mess that does not benefit me knowing in anyway. I will just assume for the foreseeable future that the Level 3 servers will work with Verizon FIOS


NetFixer
Freedom is NOT Free
Premium
join:2004-06-24
Murfreesboro, TN
·AT&T Southeast
·Vonage
·Cingular Wireless
·AT&T CallVantage


1 edit
said by kieranmullen See Profile :

Why would level3 have a hold on IP blocks from verizon? You would think that verizon would have many of its own blocks registered.
Why would Microsoft need to use Akamai Technologies servers and IP adresses? The simple answer is that corporations sub contract and sub lease services and properties from other corporations all the time.
--
History does not long entrust the care of freedom to the weak or the timid.
-- Dwight D. Eisenhower
Test your firewall.
Smell the flowers.

kieranmullen
Premium
join:2005-12-12
Portland, OR
clubs:
·Gizmo5
·Skype
·Vitelity VOIP
·magicjack.com
·Verizon FIOS
·Vonage
·ViaTalk
·VoicePulse

I believe the above lends some information on the intermixing...

said by NetFixer See Profile :

said by kieranmullen See Profile :

Why would level3 have a hold on IP blocks from verizon? You would think that verizon would have many of its own blocks registered.
Why would Microsoft need to use Akamai Technologies servers and IP adresses? The simple answer is that corporations sub contract and sub lease services and properties from other corporations all the time.


NetFixer
Freedom is NOT Free
Premium
join:2004-06-24
Murfreesboro, TN
·AT&T Southeast
·Vonage
·Cingular Wireless
·AT&T CallVantage

said by kieranmullen See Profile :

I believe the above lends some information on the intermixing...

I believe the term for this type of perpetual post buyout/merger usage is grandfathering.
--
History does not long entrust the care of freedom to the weak or the timid.
-- Dwight D. Eisenhower
Test your firewall.
Smell the flowers.


NetAdmin
CCNA

join:2008-05-22

reply to jester121
said by jester121 See Profile :

That will be a very interesting day in the IT field, when we learn who's sloppy and who's not.
Or who can remember their ISPs DNS servers. 4.2.2.2 was such a great server because it was so easy to use during an initial setup when you didn't have easy access to your ISPs DNS addresses or just plain forgot the DNS server address.
--
---
Drilling for more oil is akin to giving a methhead the keys to the meth lab.


NetFixer
Freedom is NOT Free
Premium
join:2004-06-24
Murfreesboro, TN
·AT&T Southeast
·Vonage
·Cingular Wireless
·AT&T CallVantage


1 edit
said by NetAdmin See Profile :

said by jester121 See Profile :

That will be a very interesting day in the IT field, when we learn who's sloppy and who's not.
Or who can remember their ISPs DNS servers. 4.2.2.2 was such a great server because it was so easy to use during an initial setup when you didn't have easy access to your ISPs DNS addresses or just plain forgot the DNS server address.
I think the "interesting day" and "sloppy" references are about the unknown thousands of PCs currently using the 4.2.2.x DNS servers because some tech did a quick fix 5 years ago and now nobody even remembers that it had been done.

The downtime and ISP and IT department headaches that will result on the day those DNS servers become restricted to authorized users could rival the problems caused by Blaster and Welchia.
--
History does not long entrust the care of freedom to the weak or the timid.
-- Dwight D. Eisenhower
Test your firewall.
Smell the flowers.


kontos
xyzzy

join:2001-10-04
West Henrietta, NY

reply to NetFixer
said by kieranmullen See Profile :
I suspect that that is a result of sloppy reverse DNS management on Level3's part.
Verizon (gtei.net) doesn't seep to agree that those hostnames are theirs:

and the servers appear to indicate that they are managed by Level3:


Raphion

join:2000-10-14
Samsara

reply to NetFixer
I have 4.2.2.4-5 as my DNS, but when I go to »entropy.dns-oarc.net/test/ it tells me my server names are:
1. 209.244.5.159 (ics2.Atlanta1.Level3.net)
2. 209.244.7.132 (unknown.Level3.net)
No gtei there. As I understand it, those 4.2.2.x addresses aren't actually server addresses, but rather, requests to those addresses are routed to the nearest available Level3.net DNS servers.
-
Forums » 1 In 10 DNS Servers Vulnerable To Cache Poisoning« Drinking Milk Leads to Heroin Addiction, Too!  


Thursday, 26-Nov 00:50:21 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [105] New AT&T Ad Campaign Hits Back At Verizon
· [95] Apple Joins AT&T Verizon Snark Fest
· [94] Time Warner Cable Fires Broadside At Broadcasters
· [85] New Bill Takes Aim At Higher Verizon ETFs
· [61] TiVo Sees Record Customer Losses
· [48] In-Flight Internet Headed For Bumpy Landing?
· [33] Senators Want ACTA Made Public
· [30] Earthlink Suffers From Major E-mail Outage
· [30] AT&T Offers New Prepaid Wireless plans
· [28] Frontier Increases Modem Rental Fee
Most people now reading
· Shutting of Electricity Temporarily (up to 1 yr) to Save $$$ [Home Repair & Improvement]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· What is the spell hit cap for a lvl 80 full arcane spec mage [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· I'll Just Unplug That... [No, I Will Not Fix Your #@$!! Computer]
· Looking to buy our first home. [Home Repair & Improvement]
· Whats the big deal about being "Old School"....? [World of Warcraft]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· Telemarketing Hell: Heather's back [Spam, Scam and Phishbusters]