public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-user] DNS Server Patches
@ 2008-07-27 23:03 Dan Farrell
  2008-07-28 11:08 ` Norberto Bensa
  0 siblings, 1 reply; 5+ messages in thread
From: Dan Farrell @ 2008-07-27 23:03 UTC (permalink / raw
  To: gentoo-user

The recently released (early july) advisory on the DNS exploits
discovered earlier this year have caused a bit of stir on the
BIND mailing lists, and rightly so.  Everybody on board with this one?  

CERT Bulletin:

http://www.kb.cert.org/vuls/id/800113

Dan Kiersky's own description, and web-based nameserver checker:

http://www.doxpara.com/

Alternate web-based nameserver checker (recommended by me! )

https://www.dns-oarc.net/oarc/services/dnsentropy

If your nameservers aren't updated, do so!  If your ISP's nameservers
aren't updated, hound them relentlessly until they are!  This is the
only way we can all protect the validity of our clients and our own
data.  



^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [gentoo-user] DNS Server Patches
  2008-07-27 23:03 [gentoo-user] DNS Server Patches Dan Farrell
@ 2008-07-28 11:08 ` Norberto Bensa
  2008-07-28 11:43   ` [gentoo-user] " Nikos Chantziaras
  2008-07-29  0:03   ` [gentoo-user] " Stroller
  0 siblings, 2 replies; 5+ messages in thread
From: Norberto Bensa @ 2008-07-28 11:08 UTC (permalink / raw
  To: gentoo-user

Quoting Dan Farrell <dan@spore.ath.cx>:

> Dan Kiersky's own description, and web-based nameserver checker:
>
> http://www.doxpara.com/
>
> Alternate web-based nameserver checker (recommended by me! )
>
> https://www.dns-oarc.net/oarc/services/dnsentropy

I don't get these tests. Why do they probe _my_ IP and not the IP of  
my DNS servers? What's the point on probing me if _maybe_ the servers  
are not patched?

Thanks,
Norberto

----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.





^ permalink raw reply	[flat|nested] 5+ messages in thread

* [gentoo-user]  Re: DNS Server Patches
  2008-07-28 11:08 ` Norberto Bensa
@ 2008-07-28 11:43   ` Nikos Chantziaras
  2008-07-29  4:11     ` Norberto Bensa
  2008-07-29  0:03   ` [gentoo-user] " Stroller
  1 sibling, 1 reply; 5+ messages in thread
From: Nikos Chantziaras @ 2008-07-28 11:43 UTC (permalink / raw
  To: gentoo-user

Norberto Bensa wrote:
> Quoting Dan Farrell <dan@spore.ath.cx>:
> 
>> Dan Kiersky's own description, and web-based nameserver checker:
>>
>> http://www.doxpara.com/
>>
>> Alternate web-based nameserver checker (recommended by me! )
>>
>> https://www.dns-oarc.net/oarc/services/dnsentropy
> 
> I don't get these tests. Why do they probe _my_ IP and not the IP of my 
> DNS servers? What's the point on probing me if _maybe_ the servers are 
> not patched?

Er, they *do* test the IP of your DNS server.  At least that's case 
here; it successfully tested my ISP's DNS (and told me it sucks and is 
vulnerable).




^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [gentoo-user] DNS Server Patches
  2008-07-28 11:08 ` Norberto Bensa
  2008-07-28 11:43   ` [gentoo-user] " Nikos Chantziaras
@ 2008-07-29  0:03   ` Stroller
  1 sibling, 0 replies; 5+ messages in thread
From: Stroller @ 2008-07-29  0:03 UTC (permalink / raw
  To: gentoo-user


On 28 Jul 2008, at 12:08, Norberto Bensa wrote:

> Quoting Dan Farrell <dan@spore.ath.cx>:
>
>> Dan Kiersky's own description, and web-based nameserver checker:
>>
>> http://www.doxpara.com/
>>
>> Alternate web-based nameserver checker (recommended by me! )
>>
>> https://www.dns-oarc.net/oarc/services/dnsentropy
>
> I don't get these tests. Why do they probe _my_ IP and not the IP  
> of my DNS servers? What's the point on probing me if _maybe_ the  
> servers are not patched?

Wild guess: the problem is with the client mode of operation. DNS  
servers are affected because their clients to the root name-servers.

I think this vulnerability highlights the issue of using servers that  
you TRUST.

It applies to other vulnerabilities, too. It doesn't matter if you  
revoke your SSH key and upload it to OpenForge if the OpenForge  
server itself is trusting an insecure SSH key, and an attacker can  
use it to get at your account that way.

Stroller.





^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [gentoo-user]  Re: DNS Server Patches
  2008-07-28 11:43   ` [gentoo-user] " Nikos Chantziaras
@ 2008-07-29  4:11     ` Norberto Bensa
  0 siblings, 0 replies; 5+ messages in thread
From: Norberto Bensa @ 2008-07-29  4:11 UTC (permalink / raw
  To: gentoo-user


> Norberto Bensa wrote:
>>
>> I don't get these tests. Why do they probe _my_ IP and not the IP   
>> of my DNS servers? What's the point on probing me if _maybe_ the   
>> servers are not patched?
>

Heh... I'm Sorry. I sometimes forget I run my own DNS servers :)

After changing my /etc/resolv.conf, I got my ISP's servers tested.  
They are patched.

Regards,
Norberto

----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.





^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2008-07-29  4:20 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-07-27 23:03 [gentoo-user] DNS Server Patches Dan Farrell
2008-07-28 11:08 ` Norberto Bensa
2008-07-28 11:43   ` [gentoo-user] " Nikos Chantziaras
2008-07-29  4:11     ` Norberto Bensa
2008-07-29  0:03   ` [gentoo-user] " Stroller

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox