Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 8th, 2008, 05:07 PM
ronjor's Avatar
ronjor ronjor is online now
Global Moderator
 
Join Date: Jul 2003
Location: Texas, USA
Posts: 40,690
Default Massive, coordinated DNS patch released

Quote:
On Tuesday, a security researcher responsibly disclosed a fundamental flaw within the Domain Name System (DNS), the addressing scheme behind the common names used on the Internet.

Dan Kaminsky, director of penetration testing services for IO Active, found the flaw earlier this year. Rather than sell the vulnerability, as some researchers have done, Kaminsky decided instead to gather the affected parties and discuss it with them first. Without disclosing any technical details, he said, "the severity is shown by the number of people who've gotten onboard with this patch."

He declined to name the flaw because it would give away details.
More.....
  #2  
Old July 8th, 2008, 08:12 PM
ronjor's Avatar
ronjor ronjor is online now
Global Moderator
 
Join Date: Jul 2003
Location: Texas, USA
Posts: 40,690
Default Re: Massive, coordinated DNS patch released

Researcher offers insight into DNS flaw
Quote:
At Tuesday's press conference, Kaminsky refused to provide details about the flaw, preferring to give additional vendors and administrators affected at least 30 days to create or implement the patches.

But within the conference call, during the question-and-answer session, some details and clarifications emerged.
More
  #3  
Old July 9th, 2008, 06:04 PM
axial axial is offline
Frequent Poster
 
Join Date: Jun 2007
Posts: 307
Default Re: Massive, coordinated DNS patch released

On the NetworkWorld article about the issue there's a link to Kaminsky's page with a DNS checker, would both links be appropriate to post here?
  #4  
Old July 9th, 2008, 06:09 PM
ronjor's Avatar
ronjor ronjor is online now
Global Moderator
 
Join Date: Jul 2003
Location: Texas, USA
Posts: 40,690
Default Re: Massive, coordinated DNS patch released

That will be okay.
  #5  
Old July 9th, 2008, 06:11 PM
axial axial is offline
Frequent Poster
 
Join Date: Jun 2007
Posts: 307
Default Re: Massive, coordinated DNS patch released

NetworkWorld article http://www.networkworld.com/news/200...net.html?t51hb

Kaminisky's DNS checker: http://www.doxpara.com/

Thanks, Ron.
  #6  
Old July 31st, 2008, 12:26 PM
tlu's Avatar
tlu tlu is offline
Very Frequent Poster
 
Join Date: Sep 2004
Posts: 1,052
Default Re: Massive, coordinated DNS patch released

Quote:
Originally Posted by axial
Kaminisky's DNS checker: http://www.doxpara.com/


Another one (that doesn't require Javascript) is https://www.dns-oarc.net/oarc/services/dnsentropy
__________________
Greetings, Thomas
  #7  
Old August 3rd, 2008, 10:09 AM
Rasheed187 Rasheed187 is offline
Very Frequent Poster
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 1,834
Default Re: Massive, coordinated DNS patch released

You know what I don´t understand? Why did it needed to be patched on client PC´s? I´m talking about the fix that screwed up ZoneAlarm. I mean you would think that only the DNS servers needed patching, can ayone explain?
  #8  
Old August 3rd, 2008, 03:08 PM
huangker's Avatar
huangker huangker is offline
Very Frequent Poster
 
Join Date: Nov 2007
Location: Australia
Posts: 1,244
Default Re: Massive, coordinated DNS patch released

The problem is in the DNS server not client so it is not related to ZA on your system.
__________________
Windows 7 Professional
Avast - Secunia PSI - Hostsman
Firefox - No Script - WOT - Objection
http://jeremy.gizapage.com/
  #9  
Old August 4th, 2008, 03:37 AM
Huupi Huupi is offline
Very Frequent Poster
 
Join Date: Sep 2006
Posts: 1,992
Default Re: Massive, coordinated DNS patch released

From what i have read about the flaw OpenDNS is not affected,good reason to install it. http://www.opendns.com/
  #10  
Old August 4th, 2008, 05:33 AM
tlu's Avatar
tlu tlu is offline
Very Frequent Poster
 
Join Date: Sep 2004
Posts: 1,052
Default Re: Massive, coordinated DNS patch released

Quote:
Originally Posted by huangker
The problem is in the DNS server not client so it is not related to ZA on your system.

That's not quite correct - see, e.g., the example here or here. As a matter of fact the client libraries of Windows and all Linux and BSD distributions have been patched in the meanwhile - but NOT Apple! Their client libraries still aren't patched, i.e., they haven't implemented randomization of the query ID and the source port yet.
__________________
Greetings, Thomas

Last edited by tlu : August 4th, 2008 at 05:39 AM.
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 06:38 PM.


Powered by vBulletin® Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2010, Wilders Security Forums