Re: DNS cache poisoning - Wake up everyone!
- From: Elliott Roper <nospam@xxxxxxxxx>
- Date: Wed, 06 Aug 2008 12:07:04 +0100
In article
<1il8jxz.13fb9m81ch1fsqN%usenet@xxxxxxxxxxxxxxxxxxxxxxxxxxx>, James
Taylor <usenet@xxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
Elliott Roper <nospam@xxxxxxxxx> wrote:
James Taylor <usenet@xxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
Correct. You don't need to worry about your home router trying to be a
DNS resolver. However, you do need to worry about NAT routers in an
organisation that runs its own DNS resolvers behind a NAT because, even
if the resolver uses properly randomised UDP source ports, the NAT may
unrandomise them leaving it possible to exploit the predictability of
port numbering on the outside of the NAT. A company I consult for is
having exactly this problem, and there isn't yet a firmware update for
their Fortinet routers.
I think I have something similar with the village wireless mesh network
I use (and help look after)
Could you help me with this? Which part of the NAT is unrandomising?
Is it the ADSL router facing the outside, or something inside it port
forwards to? Or some combination? Clients inside the mesh see their
nearest access node as their DNS server. When I test with doxpara's
tool it reports on the external IP address the mesh faces the world
with, POOR showing a pathetically unrandom tiny range of ports in use.
If I use dig from my Mac to doxpara's tester and use the ISPs "manual"
DNS server address it reports GREAT. The mesh boxes are some sort of
stripped down linux which lacks a dig command, so I can't test from the
gateway node, to which I have no physical access.
I think the router is a Linksys something, which I see others whinging
about on this topic, although some of them sound as clueless as me.
--
To de-mung my e-mail address:- fsnospam$elliott$$
PGP Fingerprint: 1A96 3CF7 637F 896B C810 E199 7E5C A9E4 8E59 E248
.
- Follow-Ups:
- Re: DNS cache poisoning - Wake up everyone!
- From: James Taylor
- Re: DNS cache poisoning - Wake up everyone!
- References:
- DNS cache poisoning - Wake up everyone!
- From: James Taylor
- Re: DNS cache poisoning - Wake up everyone!
- From: Woody
- Re: DNS cache poisoning - Wake up everyone!
- From: Elliott Roper
- Re: DNS cache poisoning - Wake up everyone!
- From: James Taylor
- Re: DNS cache poisoning - Wake up everyone!
- From: Elliott Roper
- Re: DNS cache poisoning - Wake up everyone!
- From: James Taylor
- DNS cache poisoning - Wake up everyone!
- Prev by Date: Re: Seven fonts that need to die
- Next by Date: Re: Hidef camcorder recommendations
- Previous by thread: Re: DNS cache poisoning - Wake up everyone!
- Next by thread: Re: DNS cache poisoning - Wake up everyone!
- Index(es):
Relevant Pages
|