<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Re: Is this legal DNS Query?&#x27; in forum &#x27;Networking&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Re-Is-this-legal-DNS-Query-27681810</link>
<description></description>
<language>en</language>
<pubDate>Sun, 19 May 2013 01:21:43 EDT</pubDate>
<lastBuildDate>Sun, 19 May 2013 01:21:43 EDT</lastBuildDate>

<item>
<title>Re: Is this legal DNS Query?</title>
<link>http://www.dslreports.com/forum/Re-Is-this-legal-DNS-Query-27696015</link>
<description><![CDATA[dnoyeB posted : The DNS query without the checksum is treated equally by the DNS servers.  Its not the lack of checksum that was the problem.  The device that was sending the request also has a bad habit of not responding to ARP requests.<br><small>--<br>dnoyeB<br>"Then said I, Wisdom [is] better than strength: nevertheless the poor man's wisdom [is] despised, and his words are not heard. " Ecclesiastes 9:16<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Is-this-legal-DNS-Query-27696015</guid>
<pubDate>Mon, 05 Nov 2012 14:54:35 EDT</pubDate>
</item>

<item>
<title>Re: Is this legal DNS Query?</title>
<link>http://www.dslreports.com/forum/Re-Is-this-legal-DNS-Query-27684442</link>
<description><![CDATA[dnoyeB posted : If I do a nslookup the computer will send a DNS request for www.fitbit.com with a proper checksum.  This gets treated properly.  Its when there is no checksum that things get strange.<br><br>I have resolved the issue down to my Zyxel USG.  It seems to be confused by the lack of a checksum.  I think its not opening a session, or prematurely closing it.  The DNS reply appears on the WAN side, but the firewall tosses it out and sends the DNS server an ICMP saying it can't find the host...<br><small>--<br>dnoyeB<br><br>"Then said I, Wisdom [is] better than strength: nevertheless the poor <br>man's wisdom [is] despised, and his words are not heard. " Ecclesiastes <br>9:16<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Is-this-legal-DNS-Query-27684442</guid>
<pubDate>Thu, 01 Nov 2012 17:05:14 EDT</pubDate>
</item>

<item>
<title>Re: Is this legal DNS Query?</title>
<link>http://www.dslreports.com/forum/Re-Is-this-legal-DNS-Query-27684158</link>
<description><![CDATA[cramer posted : It's a stupid fitbit, so security isn't on the roadmap. :-)<br><br>My guess... whatever 0.1 is doesn't like the "no checksum" udp packets.  Technically, that would be a *bad* checksum, and the OS may drop it.  All of <i>my</i> linux boxes will.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Is-this-legal-DNS-Query-27684158</guid>
<pubDate>Thu, 01 Nov 2012 16:14:46 EDT</pubDate>
</item>

<item>
<title>Re: Is this legal DNS Query?</title>
<link>http://www.dslreports.com/forum/Re-Is-this-legal-DNS-Query-27682963</link>
<description><![CDATA[Bink posted : Taking a quick glance, I don&#146;t readily see anything off.  That said, checksums are rarely disabled, so this is peculiar, and your transaction IDs are sequential, which is bad from a DNS security standpoint, so this is another red flag.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Is-this-legal-DNS-Query-27682963</guid>
<pubDate>Thu, 01 Nov 2012 12:04:12 EDT</pubDate>
</item>

<item>
<title>Re: Is this legal DNS Query?</title>
<link>http://www.dslreports.com/forum/Re-Is-this-legal-DNS-Query-27682810</link>
<description><![CDATA[HELLFIRE posted : Guessing you're referring to frames 921, 937 and 947 in your sniffer capture where 192.168.0.102 asks<br>192.168.0.1 what the IP address of www.fitbit.com is?  I guess my question at this point is does your<br>sniffer capture ever return a response from anyone for an IP address of www.fitbit.com at all or not?<br><br>I'm really rusty on my DNS so I'd have to do a bit of refresher reading into this.<br><br>Regards]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Is-this-legal-DNS-Query-27682810</guid>
<pubDate>Thu, 01 Nov 2012 11:17:18 EDT</pubDate>
</item>

<item>
<title>Is this legal DNS Query?</title>
<link>http://www.dslreports.com/forum/Is-this-legal-DNS-Query-27681810</link>
<description><![CDATA[dnoyeB posted : As I understand it, the checksum in UDP packets is optional.  So why are these queries being ignored??<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/27681810?c=2046956&ret=L2ZvcnVtL3IyNzY5NjAxNS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="500266 bytes" WIDTH=600 HEIGHT=330 SRC="/r0/download/2046956.thumb600~538093396a061d7690c1cde4315dcddb/dnsquery.jpg/thumb.jpg" ALT="Click for full size"></A><br>failed query</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Is-this-legal-DNS-Query-27681810</guid>
<pubDate>Thu, 01 Nov 2012 01:25:19 EDT</pubDate>
</item>

</channel>
</rss>
