DNS Exploit in the Wild

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

StarsFan4Life

Golden Member
May 28, 2008
1,199
0
0
What are the new servers?

Would I need to do anything in my D-Link router as well?

Would a DNS flush not work?
 

effowe

Diamond Member
Nov 1, 2004
6,012
18
81
Originally posted by: StarsFan4Life
What are the new servers?

Would I need to do anything in my D-Link router as well?

Would a DNS flush not work?

You would want to do it at router level so that any PC's connected to that router will all be unaffected. If your DNS servers (from the router's) settings are vulnerable, then your other machines will be affected. If you just change it on your personal PC, it wont affect your PC, but will the others. DNS flush would not work as far as I know.
 

StarsFan4Life

Golden Member
May 28, 2008
1,199
0
0
Originally posted by: effowe
Originally posted by: StarsFan4Life
What are the new servers?

Would I need to do anything in my D-Link router as well?

Would a DNS flush not work?

You would want to do it at router level so that any PC's connected to that router will all be unaffected. If your DNS servers (from the router's) settings are vulnerable, then your other machines will be affected. If you just change it on your personal PC, it wont affect your PC, but will the others. DNS flush would not work as far as I know.

Ok, so what do I need to change the DNS servers to?
 

effowe

Diamond Member
Nov 1, 2004
6,012
18
81
Originally posted by: StarsFan4Life
Ok, so what do I need to change the DNS servers to?

208.67.222.222
208.67.220.220

(for the third time in this thread)
 

StarsFan4Life

Golden Member
May 28, 2008
1,199
0
0
Originally posted by: effowe
Originally posted by: StarsFan4Life
Ok, so what do I need to change the DNS servers to?

208.67.222.222
208.67.220.220

(for the third time in this thread)

Thanks.

Now, in my D-Link Di-524 router, I do not have the option to change the DNS servers. I do have a DHCP release and renew. Is this what I want?

Currently, my dns servers are:

24.93.41.127
24.93.41.128
 

jonks

Lifer
Feb 7, 2005
13,918
20
81
Originally posted by: StarsFan4Life
So how big of a deal is this? The "older" guys at work here all are worried that the "internet" is going down soon.

Don't worry. If the Internet goes down, I'm planning on heading out Californeeway. I heard there's some Internet out there. It'll be a long haul. Maybe we can caravan and seek it out together.
 

effowe

Diamond Member
Nov 1, 2004
6,012
18
81
Originally posted by: StarsFan4Life
Originally posted by: effowe
Originally posted by: StarsFan4Life
Ok, so what do I need to change the DNS servers to?

208.67.222.222
208.67.220.220

(for the third time in this thread)

Thanks.

Now, in my D-Link Di-524 router, I do not have the option to change the DNS servers. I do have a DHCP release and renew. Is this what I want?

Currently, my dns servers are:

24.93.41.127
24.93.41.128

Look under WAN settings, maybe under advanced, there is in option in there. I am looking at page 15 of your routers manual and it says the WAN tab on the left, Home tab on the top you can change them.
 

StarsFan4Life

Golden Member
May 28, 2008
1,199
0
0
Originally posted by: effowe
Originally posted by: StarsFan4Life
Originally posted by: effowe
Originally posted by: StarsFan4Life
Ok, so what do I need to change the DNS servers to?

208.67.222.222
208.67.220.220

(for the third time in this thread)

Thanks.

Now, in my D-Link Di-524 router, I do not have the option to change the DNS servers. I do have a DHCP release and renew. Is this what I want?

Currently, my dns servers are:

24.93.41.127
24.93.41.128

Look under WAN settings, maybe under advanced, there is in option in there. I am looking at page 15 of your routers manual and it says the WAN tab on the left, Home tab on the top you can change them.

I changed them to:

208.67.222.222
208.67.220.220

Now when I check doxpara.com I get this.

Your name server, at 208.69.32.12, appears to be safe, but make sure the ports listed below aren't following an obvious pattern.
--------------------------------------------------------------------------------





Am I safe now?
 

effowe

Diamond Member
Nov 1, 2004
6,012
18
81
Originally posted by: StarsFan4Life
I changed them to:

208.67.222.222
208.67.220.220

Now when I check doxpara.com I get this.

Your name server, at 208.69.32.12, appears to be safe, but make sure the ports listed below aren't following an obvious pattern.

Am I safe now?

I would say so, at least concerning this particular vulnerability.
 

StarsFan4Life

Golden Member
May 28, 2008
1,199
0
0
Originally posted by: effowe
Originally posted by: StarsFan4Life
I changed them to:

208.67.222.222
208.67.220.220

Now when I check doxpara.com I get this.

Your name server, at 208.69.32.12, appears to be safe, but make sure the ports listed below aren't following an obvious pattern.

Am I safe now?

I would say so, at least concerning this particular vulnerability.

What do you mean at least?
 

torpid

Lifer
Sep 14, 2003
11,631
11
76
Originally posted by: Joemonkey
Originally posted by: Modelworks
Well it didn't take long for the exploit to start making rounds. This one could be really bad if it isn't patched on servers soon. I just checked my isp servers and they are vulnerable. I won't give out the isp name, its a major one though, with thousands of customers. I emailed them to tip them off, I shouldn't have had to, but hopefully they patch it soon.

Why not just come out and say AT&T?

More info here: http://www.kb.cert.org/vuls/id/800113

Ugh. Just tested my iPhone and it's vulnerable. I don't see any obvious way to alter the DNS settings over Edge.
 

effowe

Diamond Member
Nov 1, 2004
6,012
18
81
Originally posted by: StarsFan4Life
What do you mean at least?

I mean as far as the DNS vulnerability, you are safe. Your computer could be open to attack from a million other sources, but I have no idea about your network setup or computer habits so I couldn't tell ya.
 

StarsFan4Life

Golden Member
May 28, 2008
1,199
0
0
We tested it here:

Your name server, at 64.129.67.XXX, appears to be safe, but make sure the ports listed below aren't following an obvious pattern

However, this IP is not the DNS server we use. Is this test even legit or correct?
 

iamwiz82

Lifer
Jan 10, 2001
30,772
13
81
Originally posted by: StarsFan4Life
We tested it here:

Your name server, at 64.129.67.XXX, appears to be safe, but make sure the ports listed below aren't following an obvious pattern

However, this IP is not the DNS server we use. Is this test even legit or correct?

It's testing whatever your DNS is set to, not necessarily the ISP.

Also, regarding your port pattern issue, I had to turn on the scambling functionality on my Checkpoint box.
 

StarsFan4Life

Golden Member
May 28, 2008
1,199
0
0
Originally posted by: iamwiz82
Originally posted by: StarsFan4Life
We tested it here:

Your name server, at 64.129.67.XXX, appears to be safe, but make sure the ports listed below aren't following an obvious pattern

However, this IP is not the DNS server we use. Is this test even legit or correct?

It's testing whatever your DNS is set to, not necessarily the ISP.

Also, regarding your port pattern issue, I had to turn on the scambling functionality on my Checkpoint box.

Well, our DNS is NOT set to the IP above, rather a completely different ip.
 

Gooberlx2

Lifer
May 4, 2001
15,381
6
91
Originally posted by: StarsFan4Life
Originally posted by: Gooberlx2
Still vulnerable. I wonder if our IT dept even knows about this.

Was this referenced to me?

No. I was more or less making a commentary about my employer's IT dept.....unless you work for my employer, and now I'm in trouble.

*shifty eyes*
 

StarsFan4Life

Golden Member
May 28, 2008
1,199
0
0
Originally posted by: Gooberlx2
Originally posted by: StarsFan4Life
Originally posted by: Gooberlx2
Still vulnerable. I wonder if our IT dept even knows about this.

Was this referenced to me?

No. I was more or less making a commentary about my employer's IT dept.

Weird because not but 5 minutes before that I sent an email to my fiances company that IS vulnerable and asked if their IT department even knew about it.
 

iamwiz82

Lifer
Jan 10, 2001
30,772
13
81
Originally posted by: StarsFan4Life
Originally posted by: iamwiz82
Originally posted by: StarsFan4Life
We tested it here:

Your name server, at 64.129.67.XXX, appears to be safe, but make sure the ports listed below aren't following an obvious pattern

However, this IP is not the DNS server we use. Is this test even legit or correct?

It's testing whatever your DNS is set to, not necessarily the ISP.

Also, regarding your port pattern issue, I had to turn on the scambling functionality on my Checkpoint box.

Well, our DNS is NOT set to the IP above, rather a completely different ip.

The IP above is the public IP that is probably NATed on your firewall. The firewall knows your DNS servers' IPs. Your firewall should also be scrambling the NATed ports.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |