PDA

View Full Version : Multiple DNS queries for website IP verification to prevent DNS poisoning?


rubixcube
March 16th, 2011, 03:36 PM
What is the way of ensuring you are not the victim of DNS poisoning and sent to a fake phishing site because of a compromised DNS lookup server?

Is it possible to have a setup whereby you rely on multiple trusted public DNS lookup servers to query a website's IP before your browser connects to the site?

What are other ways of protecting against a compromised DNS lookup server, even the trusted ones like OpenDNS, Google's DNS, etc? It seems by default, Windows relies on one single DNS lookup server only. You can add backup DNS lookup servers in the IP settings, but it is only still just relying on one server.

BoerenkoolMetWorst
March 16th, 2011, 03:39 PM
Some software like Online Armor Premium and Prevx SOL verify the IP address with their own database/DNS, but I don't think it's possible to let a computer use two different DNS servers at the same time.

rubixcube
March 17th, 2011, 03:09 PM
Im kinda surprised this is not an option or noone has implimented something along the lines.

So basically you should manual doublecheck yourself and IP link to the site... for max security?

Acadia
March 17th, 2011, 07:53 PM
Simply add your financial institutions to your Hosts file.

Acadia

Sadeghi85
March 17th, 2011, 08:54 PM
You might want to ask Acrylic DNS Proxy developer to add this feature.

-{ Quote: "It would be possible to further reduce Acrylic vulnerability to cache poisoning by ensuring that before an entry is written into the cache: (1) All the responses coming from the DNS servers agree with each other. (2) The almost identical requests sent to the DNS servers have all different truly random Query IDs. (3) The Query ID of each response coming from the DNS servers matches with the request.

This kind of “HighSecure” mode would have the side effect of slightly longer name resolution times and decreased fault tolerance in case some of the DNS servers fail but with two DNS servers configured the previously explained attack against Acrylic in “HighSecure” mode would have a 50% probability to succeed in 90.000 years and with three DNS servers (the maximum allowed) a 50% probability to succeed in 6 billions years. Although not currently on my high priority list this feature would be an interesting thing to have and I will definitely dedicate some other thoughts to it." }-

-http://mayakron.altervista.org/support/browse.php?path=Acrylic&name=FAQ