Welcome to Welcome to DNF.com™ - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars

If you are new to domains and looking to buy, sell and learn about domains then you have come to the right place. DNForum is the largest domain name community on the internet and continues to grow every day. There are over 105,000 domainers on DNForum doing everything from buying domains, selling domains, learning about domains and discussing domains. Take a minute and Register.

Register Today on DNForum IT'S FREE!

Results 1 to 13 of 13
  1. #1
    Exclusive Lifetime Member
    Tia Wood's Avatar
    Join Date
    Jan 2006
    Location
    Florida
    Posts
    3,675
    Country

    United States
    DNF$
    539
    Bank
    2,627
    Total DNF$
    3,166
    Donate  

    Full Explanation of DNS Security Hole No Other Domainer Seems Worried About But Me.

    I posted a thread about the DNS security hole which received no response from domainers. Perhaps I should have explained that it totally disables your ability to earn revenue from affiliates and parking programs, if effected.

    Oh, and it doesn't need your consent nor trip any alarms of any kind and rendors your firewalls, usernames and passwords completely useless, not to mention it doesn't need your ISP, Hosting server or domain company's permission to do what it wants with your domain.

    Full Article >>

    Quote from Article:

    This past week at Black Hat 2008, Kaminsky finally revealed the actual details of the bug he discovered. The design flaw makes it a great deal easier to poison a name server’s cache, voiding any trust in query results from that name server. In order to understand the magnitude of the bug, we need to be familiar with how a DNS query works, so lets’ start there.
    In my example, I’m controlling when my ISP’s name server is sending out a DNS query. If my query for 11.techrepublic.com didn’t work, all I have to do is try 12.techrepublic.com and go through the same process until I get a collision. I’ll know when that happens, as I’ll get DNS information for 11 or 12.techrepublic.com from my ISP.

    There are several concepts in play here that make this cache poisoning attack vector extremely onerous, they are:

    * Since the DNS query response was “in bailiwick”, my ISP’s name server thinks the IP addresses that I gave it are authoritative for the whole techrepublic.com domain.
    * I can set the TTL of the FQDN/IP address information to an extremely large amount; it’s a 32-bit number. That way the false DNS information will not expire.
    * I can now setup phishing web sites that will not trip any alarms or phishing filters.
    * This design flaw is present in every recursive name server.
    More details here:

    An Illustrated Guide to the Kaminsky DNS Vulnerability (excellent read)
    New exploit poisons patched DNS servers, claims researcher
    ISACA Says Major DNS Flaw Affecting Email Comes as No Surprise
    Apple Security Patch Flubs DNS Fix

    More Reading:

    Seems to be something we can do for now:

    Seems to be a service called "OpenDNS" is what people are switching to for now. I'm not sure how it works but worth looking into. However, there is one downside:

    Note that OpenDNS is able to provide its services for free because it changes how your browser behaves when you enter a non-existent URL, say for asdfjklasjxznn.com. If you enter that URL using your normal DNS servers, you'll get a standard "page not found" error message. If you load that URL using OpenDNS, however, you'll see the image at right (click the image for a larger version). The ads you see there are what help OpenDNS pay for its services. If the prospect of seeing such ads when you enter a bad URL concerns you, then you'll want to pass on this solution. For me, though, it's a small price to pay for an excellent free service.
    More Ways to Protect Yourself From Phishing
    OpenDNS Offers DNS Vulnerability Protection
    OpenDNS Wildly Popular After Kaminsky Flaw Disclosure

    Smaller ISPs at risk to DNS flaw

    Telstra, Optus, Internode and iiNet have confirmed to Computerworld their DNSs are patched, however, sources reveal many DNS admins have yet to fix the flaw, despite being notified by security researchers, and nagged by concerned ISPs and Web masters.
    Patch domain name servers now, says DNS inventor

    Paul Mockapetris, inventor of the Internet's Domain Name System architecture, has some advice for those in any doubt about the seriousness of a weakness in the DNS protocol that was disclosed yesterday: Patch your DNS servers right now.

    The vulnerability and the attack it enables are among the most dangerous to have been discovered in the DNS protocol so far, Mockapetris said in an interview with Computerworld Wednesday morning.

    "It's absolutely critical for IT managers to upgrade their software. They want to make very sure that the caching servers on their perimeters are up to snuff," Mockapetris said. In addition, they need to also ensure that client devices such as DSL modems that might have DNS software embedded in them are properly patched. "The time to fix is now. The clock is ticking," before exploits against the flaw become widely available, he said.
    Is Your Domain Parking Service Vulnerable to DNS Cache Poisoning?
    Many domainers don’t own web sites, but they certainly have their domains parked on other people’s name servers. Are you vulnerable? Internet Assigned Numbers Authority (IANA) has a new tool available to find out.

    I tested the nameservers for many of the parking companies and found they are safe: Parked.com , sedo , and Dotzup .
    Microsoft warns: get your DNS flaw fix now

    Microsoft is not currently aware of active attacks utilizing this exploit code or of customer impact at this time. However, attacks are likely imminent due to the publicly posted proof of concept and Microsoft is actively monitoring this situation to keep customers informed and to provide customer guidance as necessary. Microsoft’s investigation of this exploit code has verified that it does not affect Microsoft customers who have installed the updates detailed in Microsoft Security Bulletin MS08-037.
    A cheatsheet for defending against the DNS flaw

    The only omission in their instructions is the need to make this change for every type of network connection. On a laptop computer, for example, you would need to modify both the network connection for wired Ethernet and also the Wi-Fi network connection. If you use dial-up, that too, needs to be modified.
    Last edited by Tia Wood; 08-11-2008 at 04:35 PM.

  2. #2
    fab's Avatar
    Join Date
    Dec 2004
    Location
    Elad
    Posts
    5,044
    Country

    United States
    DNF$
    33,889
    Bank
    0
    Total DNF$
    33,889
    Donate  
    You seem to be a real Techy Mega!

  3. #3
    Exclusive Lifetime Member
    Tia Wood's Avatar
    Join Date
    Jan 2006
    Location
    Florida
    Posts
    3,675
    Country

    United States
    DNF$
    539
    Bank
    2,627
    Total DNF$
    3,166
    Donate  
    Quote Originally Posted by fab View Post
    You seem to be a real Techy Mega!
    I'm assuming you think I wrote the article, lol. Michael Kassner did here.

  4. #4
    JewelryRelated.com
    stock_post's Avatar
    Join Date
    Sep 2006
    Location
    Sharp Directory
    Posts
    2,826
    DNF$
    32,559
    Bank
    0
    Total DNF$
    32,559
    Donate  
    What can do about the threat? (as individual or small domain owner)
    Medical and Health Directory |
    Health Directory |

    Hostgator Hosting Coupon -- hostbidscom -- Save $9.94

  5. #5
    Exclusive Lifetime Member
    Tia Wood's Avatar
    Join Date
    Jan 2006
    Location
    Florida
    Posts
    3,675
    Country

    United States
    DNF$
    539
    Bank
    2,627
    Total DNF$
    3,166
    Donate  
    Quote Originally Posted by stock_post View Post
    What can do about the threat? (as individual or small domain owner)
    Unfortunately there's nothing you or we can do. It's something on the hardware, ISP, software end that each provider needs to patch. They seem to be moving quick about it (but not fast enough imo). I'm not a computer tech by any means but one doesn't need to be to understand how serious this can get.

    For those that still don't understand: DNS is the core of how domain names resolve to IPs on the internet. For instance, every time you point a domain using nameservers, that is dependent on DNS technology. What this vulnerability does is allow a malicious user to resolve your domain name to any webserver, parking page, etc that he/she wants.

    It doesn't seem to be anything that should cause a wide spread panic right now unless a bunch of websites start doing weird things. However, I'm just completely amazed at this vulnerability as we all had complete trust in the way DNS works.

    Anyone else as scared as I am, lol?

    More details here:

    An Illustrated Guide to the Kaminsky DNS Vulnerability (excellent read)
    New exploit poisons patched DNS servers, claims researcher
    ISACA Says Major DNS Flaw Affecting Email Comes as No Surprise
    Apple Security Patch Flubs DNS Fix
    Last edited by Tia Wood; 08-11-2008 at 03:59 PM.

  6. #6
    Gold Lifetime Member
    HarveyJ's Avatar
    Join Date
    Feb 2008
    Location
    Australia
    Posts
    693
    Blog Entries
    9
    DNF$
    5,977
    Bank
    0
    Total DNF$
    5,977
    Donate  
    Tia, the problem isn't that people don't care, it's just that most people here can't do a thing about it.
    I've noticed that both on the domaining and affiliate marketing forums, most people have very little concept of how networked systems, or even computers, actually operate. There's a real irony in that nerds aren't the ones monetizing the internet. They're usually too busy plugging away in (relatively) low paying coding jobs to make the infrastructure that makes other people really rich.
    I'd say this is the reason why there are even people on this forum that think that Y2K was a hype issue (and one person that even seems to think there wasn't even a problem because nothing bad actually seemed to happen)

    Also, I cast doubt on your nerdiness...
    Everyone knows women can't be nerds unless grotesque in appearance

  7. #7
    DNF Addict
    south's Avatar
    Join Date
    Dec 2006
    Location
    33143/04930
    Posts
    4,994
    DNF$
    8,195
    Bank
    0
    Total DNF$
    8,195
    Donate  

  8. #8
    WebsiteTraders.Com's Avatar
    Join Date
    Jan 2008
    Location
    DNF
    Posts
    546
    Blog Entries
    1
    DNF$
    1,891
    Bank
    0
    Total DNF$
    1,891
    Donate  
    another reason to have a quality host & registrar.

  9. #9
    Platinum Lifetime Member

    Join Date
    Jul 2007
    Location
    Hershey, PA
    Posts
    94
    DNF$
    307
    Bank
    0
    Total DNF$
    307
    Donate  
    Quote Originally Posted by WebsiteTraders.Com View Post
    another reason to have a quality host & registrar.
    It doesn't matter who your registrar is. What matters are ISP's that are unpatched.

    Say you own exampledomain.com, and my ISP is unpatched. Someone could execute this attack, create a dns entry for exampledomain.com that your ISP would cache, and then anyone connected to the internet through my unpatched ISP who queries that domain will be brought to the IP address that the attacker specified.
    Last edited by hyped; 08-12-2008 at 06:29 PM. Reason: typo

  10. #10
    www.ehot.net
    Stian's Avatar
    Join Date
    Jan 2007
    Location
    EHOT.net
    Posts
    7,361
    Country

    Norway
    DNF$
    4,442
    Bank
    0
    Total DNF$
    4,442
    Donate  
    Great article Tia! I have read a little about the DNS exploit earlier, but you've really put together an excellent post which explains it all. Thanks!

  11. #11
    Domainer
    simon johnson's Avatar
    Join Date
    Dec 2005
    Location
    Melbourne, Aust
    Posts
    237
    Country

    Australia Follow simon johnson On Twitter Add simon johnson on Facebook Visit simon johnson's Youtube Channel
    DNF$
    2,385
    Bank
    0
    Total DNF$
    2,385
    Donate  

    Cool

    Great post Tia.

    As a domainer, entrepreneur and closet techo I'm not overly concerned. The majority of hard core unix geeks that need to patch their DNS servers have already done so.

    The only thing out of left field which could come and bite you is if you have your own DNS server running on a dedicated server somewhere. If you have some sort of CPanel installed that's not set to automatically update patches etc.. then you'll probably be in a bit of trouble.

    For me its the old 80/20 rule. Most people will patch, but there will be a few big corporates that will get caught out and hit.

    Personally I wouldn't use OpenDNS as I don't know enough about them to trust the service. They are also ad supported (thats how they offer it for free) and I really don't want more ads in my life. Aside from that they have typo filters and things that probably don't gel with the average domainer. ;-)

  12. #12
    Platinum Lifetime Member
    cyberdomainer's Avatar
    Join Date
    May 2008
    Location
    australia
    Posts
    28
    DNF$
    296
    Bank
    0
    Total DNF$
    296
    Donate  
    Great post, it worries me as well

  13. #13
    I suppose it depends how many domainers have sites that earn revenues large enough to make it a target for someone to explicitly create a poisoned record for

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Domain name forum recommended by Domaining.com