Major page UPDATE: 22/06/2008.
Lilypie 1st Birthday PicLilypie 1st Birthday Ticker

Lilypie 3rd Birthday PicLilypie 3rd Birthday Ticker Morgan Storey's Journal.

Thursday, August 14, 2008

DNS woes continue... sorta 

So as I said, and the original discoverer Dan said, it was just a patch. Not a fix, not a be-all and end all solution. A temporary patch. We already know some nat devices break the patch's fix. But from the looks here and here it can be broken. The first link even details how, but there is a caveat. It is not easy, and a lot of bandwidth with low latency is required.
The first article explains how they did it over Gige in 10 hours. So most DNS servers that are doing resolves for clients, are probably not even on 20mbs of bandwidth, and latency 10+ times that of ethernet, not including the clients themselves causing some load. So you could say it would take 10+ times longer to do this over the internet, so 100hours. Someone will hopefully notice at around hour 20… But it isn't that simple, what if some baddie hits a server with a mere 100 clients... (Most botnets are 10 times this size). Chaos again. We need a better fix. I mentioned before some kind of signed DNS, I am the first to admit I have gaps in my knowledge as I have never heard of DNSSEC, now I that have listened to the Blackhat talk I have heard about it. I had a quick look at wikipedia and the official site and it is interesting. Of course windows servers only support it as a secondary, also the glaring-hole of non NSEC3 servers allowing enumeration of sites is just plain silly. Seriously just hash The users request domain “Not Found” and add it to the RFC, done.
I think it should include the option for encrypting replies, may as well, could be useful for higher secure organisations.
This is a very real and very now threat, there are at least two pieces of software out there to attack it, one being the very good, but very newbie friendly metasploit.
Well I am pretty much just re-iterating and expanding on my comments on darknet but there you go.
Peace out all.

Labels: ,


Comments: Post a Comment

Archives

07/01/2003 - 08/01/2003   08/01/2003 - 09/01/2003   09/01/2003 - 10/01/2003   10/01/2003 - 11/01/2003   11/01/2003 - 12/01/2003   12/01/2003 - 01/01/2004   01/01/2004 - 02/01/2004   02/01/2004 - 03/01/2004   03/01/2004 - 04/01/2004   04/01/2004 - 05/01/2004   05/01/2004 - 06/01/2004   07/01/2004 - 08/01/2004   09/01/2004 - 10/01/2004   11/01/2004 - 12/01/2004   12/01/2004 - 01/01/2005   01/01/2005 - 02/01/2005   02/01/2005 - 03/01/2005   03/01/2005 - 04/01/2005   04/01/2005 - 05/01/2005   05/01/2005 - 06/01/2005   06/01/2005 - 07/01/2005   07/01/2005 - 08/01/2005   08/01/2005 - 09/01/2005   09/01/2005 - 10/01/2005   10/01/2005 - 11/01/2005   11/01/2005 - 12/01/2005   12/01/2005 - 01/01/2006   03/01/2006 - 04/01/2006   05/01/2006 - 06/01/2006   06/01/2006 - 07/01/2006   07/01/2006 - 08/01/2006   09/01/2006 - 10/01/2006   11/01/2006 - 12/01/2006   09/01/2007 - 10/01/2007   04/01/2008 - 05/01/2008   05/01/2008 - 06/01/2008   06/01/2008 - 07/01/2008   07/01/2008 - 08/01/2008   08/01/2008 - 09/01/2008   09/01/2008 - 10/01/2008   11/01/2008 - 12/01/2008  

This page is powered by Blogger. Isn't yours?

 

 

Home
  Mobile Blog
  Security Blog
About me
Fiona
My Friends
My Computers
About LRP
My Family
Message board
My Jaunts
My Projects
My Resume
Other Journals
Downloads
Links

E-mail Me

No Clean Feed - Stop Internet Censorship in Australia

RSS Feed        Atom Feed
RSS or ATOM

 

 

Fight Spam!