LGF

more options

  

Advertisement

DNS Attack Code Released

Thu, Jul 24, 2008 at 5:38:19 pm PDT

If you think you’ve had a tough week, imagine what some system administrators at major ISPs and network operations centers are going through to patch millions of DNS servers against this undetectable “phishing” attack.

Dan Kaminsky’s blog has a tool that does a quick check to tell you if the DNS servers you’re using are vulnerable to the attack.

Advertisement

131 comments

  • Comments are open and unmoderated, and do not necessarily reflect the views of Little Green Footballs.
  • Obscene, abusive, silly, or annoying remarks may be deleted, but the fact that particular comments remain on the site in no way constitutes an endorsement of their views by Little Green Footballs.
  • Posts that contain phone numbers, street addresses, email addresses or other personal information will also be deleted, as will posts that consist only of a variation on the word, "First!"
  • Comments that advocate violence will be cause for immediate banning with no appeal.
  • Disagreement and debate are welcome, but insults and abuse are not, and may cause your account to be blocked.
  • REMEMBER: posting comments at LGF is a privilege, not a right. Abuse that privilege, and your account will be blocked.

Hide comments | Jump to bottom

1 Whiterasta  Thu, Jul 24, 2008 5:41:08pm

psssst... I have inherited a billion dollars from my uncle.

Help me launder it and I will give you a million dollars.

2 infidel Alan  Thu, Jul 24, 2008 5:41:56pm

Feed my internet paranoia...

3 CyanSnowHawk  Thu, Jul 24, 2008 5:42:12pm

Should be an interesting few days on the internet.

4 Racer X  Thu, Jul 24, 2008 5:42:52pm

*eyes room*

5 Walter L. Newton  Thu, Jul 24, 2008 5:43:48pm

What does this have to do with radical Islam?

/

6 Sharmuta  Thu, Jul 24, 2008 5:44:22pm

Thanks for keeping us aware of this problem, Charles. I mentioned the earlier attack to my boss at work, and he hadn't heard about it. Made me feel in the know.

7 Whiterasta  Thu, Jul 24, 2008 5:44:31pm

re: #5 Walter L. Newton

Where do you think this comes from?

8 Cognito  Thu, Jul 24, 2008 5:45:16pm

John Hero: "Help me out, here, Whiz. I'm blind in this elevator shaft."

Whiz: "Just a sec. I'm patching the network."

Hero: "The ventilation fan is set to kick on any sec, Whiz --"

Whiz: "Gimme time, Johnny!"

Hero: "Ten seconds!"

Whiz: "The ISPs are tangled in the DNS from X-Force ISS!"

Hero: "Five seconds! Help me out here -- three -- two --"

Whiz: "We're in!"

Hero: "About time, kid. About time."

9 Walter L. Newton  Thu, Jul 24, 2008 5:45:43pm

re: #6 Sharmuta

Thanks for keeping us aware of this problem, Charles. I mentioned the earlier attack to my boss at work, and he hadn't heard about it. Made me feel in the know.

And you can email these two links above to your friends. I have a number of friends who are not a savey (sp?) on computers, and I always try to keep them up to date on these types of concerns.

10 Walter L. Newton  Thu, Jul 24, 2008 5:46:30pm

re: #7 Whiterasta

Where do you think this comes from?

Whitey. It was a joke. Didn't you see my sarcasm tag?

11 Big Steve  Thu, Jul 24, 2008 5:46:56pm

Call me illiterate but what is 'phishing'. I think I know but am not sure

12 Whiterasta  Thu, Jul 24, 2008 5:47:08pm

re: #10 Walter L. Newton

Dude... Sorry. I missed it! Duuuuuh!

13 MadNachos  Thu, Jul 24, 2008 5:47:23pm

Any sysadmin worth their salt has already patched their DNS servers...everyone knew pretty much what the exploit was and knew it would be out 'in the wild' shortly after the issue was announced a few weeks ago.

14 EC Marm  Thu, Jul 24, 2008 5:48:07pm

Comcast just changed to a new DNS system the past week. Looks safe:

Your name server, at [redacted], appears to be safe, but make sure the ports listed below aren't following an obvious pattern.
15 Silhouette  Thu, Jul 24, 2008 5:48:11pm

re: #11 Big Steve

Call me illiterate but what is 'phishing'. I think I know but am not sure

When a mommy and a daddy love each other very much...

/jk

Internet "fishing" for personal information - trying to get your passwords, account numbers, etc.

16 Lucius Septimius  Thu, Jul 24, 2008 5:48:15pm

Our IT folks have been on top of this -- I ended up telling a friend who works at ATT about stuff before they were officially told.

This, of course, is the same ATT that is making it difficult for its employees to telecommunte.

17 ted  Thu, Jul 24, 2008 5:48:29pm

OMG, I'm vulnerable. Now what?

18 Walter L. Newton  Thu, Jul 24, 2008 5:48:30pm

re: #11 Big Steve

Call me illiterate but what is 'phishing'. I think I know but am not sure

Where a scammer presents you with a website that looks like a site you are familiar with, like your bank, and you type in your password and stuff and bingo, they have your info.

Or an eamil that asks you for personal info, and it looks like it came from a ligit source.

It is slang for "fishing," as in fishing for information.

19 Dolphin  Thu, Jul 24, 2008 5:49:03pm

re: #6 Sharmuta

I was just debating on whether I should e-mail one of our system admins at work. It's almost 8:00pm here, but we are world wide (so other offices are open).

They are usually up on this kind of thing.

20 Whiterasta  Thu, Jul 24, 2008 5:49:04pm

re: #11 Big Steve

Internet fraud. How to separate the ignorant from their money.

21 EC Marm  Thu, Jul 24, 2008 5:49:08pm

re: #11 Big Steve

Call me illiterate but what is 'phishing'. I think I know but am not sure


Don't worry about it. If you give me your credit card info and PIN number I'll make sure you're safe.

/ get it?

22 Walter L. Newton  Thu, Jul 24, 2008 5:49:14pm

re: #17 ted

OMG, I'm vulnerable. Now what?

Contact your ISP and ask them why they haven't applied the new patch.

23 Big Steve  Thu, Jul 24, 2008 5:50:23pm

re: #21 EC Marm

oh ok.......bank number is 34256785647 PIN = YOUSUCK

24 Lucius Septimius  Thu, Jul 24, 2008 5:50:25pm

One interesting version are ones pretending to be tracking notices on UPS shipments. One got picked up today in the filter that was supposedly a notice from the US Customs service regarding a shipment I was supposedly expecting.

25 Walter L. Newton  Thu, Jul 24, 2008 5:50:35pm

re: #21 EC Marm

Don't worry about it. If you give me your credit card info and PIN number I'll make sure you're safe.

/ get it?

LOL

26 Killgore Trout  Thu, Jul 24, 2008 5:51:16pm

How will the effect pr0n?

27 Sharmuta  Thu, Jul 24, 2008 5:51:56pm

re: #9 Walter L. Newton

And you can email these two links above to your friends. I have a number of friends who are not a savey (sp?) on computers, and I always try to keep them up to date on these types of concerns.

Not a bad idea- the resident geek at work was also unaware until I told him about it. Now I'll get to look really smart again when I tell them tomorrow there is another DNS issue going on. They will be impress.

28 Walter L. Newton  Thu, Jul 24, 2008 5:52:31pm

I remember a number of years ago, I signed on to Ebay and instead of getting my home page, I got a page, looked like an Ebay page, asking me for updated information.

Hackers had somehow imbedded a redirect to a phishing site. It wasn't an Ebay page.

I knew better, because I knew that should never happen.

29 LEGION  Thu, Jul 24, 2008 5:52:35pm

Just stay on LGF and don't give out info. Safe and sound. Ahhhhh.

30 Lucius Septimius  Thu, Jul 24, 2008 5:52:38pm

re: #26 Killgore Trout


At least half the ones I see netted up in the filter are purportedly that sort of thing. Then there are horrible news headlines.

31 CyanSnowHawk  Thu, Jul 24, 2008 5:53:06pm

re: #13 MadNachos

Any sysadmin worth their salt has already patched their DNS servers...everyone knew pretty much what the exploit was and knew it would be out 'in the wild' shortly after the issue was announced a few weeks ago.

The problem is with testing their systems. That takes time. So you don't blindly apply a patch to all your systems at once. You don't want to run into the problem that Zone Alarm users ran into with the MS patch for this problem. It stopped my system from connecting to the internet. You get a similar problem on your DNS servers, and you are offline, which is a state you don't want.

32 Walter L. Newton  Thu, Jul 24, 2008 5:53:56pm

re: #27 Sharmuta

Not a bad idea- the resident geek at work was also unaware until I told him about it. Now I'll get to look really smart again when I tell them tomorrow there is another DNS issue going on. They will be impress.

Well, it's the same issue, it's just that the actual hack code has gone public, instead of just being available among a few select hackers.

Now every nut case in their basement can try to play with this if they have the chops.

33 LEGION  Thu, Jul 24, 2008 5:54:31pm

Where is it coming from? China or Russia? Or another bad actor. Kids from the Philippines? So dumb.

34 CyanSnowHawk  Thu, Jul 24, 2008 5:54:42pm

re: #17 ted

OMG, I'm vulnerable. Now what?

Stay away from internet banking and shopping until it's patched, those would be the main targets.

35 Dolphin  Thu, Jul 24, 2008 5:54:52pm

Question - if I VPN'ed into work and logged onto my computer there and ran the test would it detect the servers at work or my home ISP. If this does not make any sense, then this is really over my head.

36 LEGION  Thu, Jul 24, 2008 5:55:17pm

We'll never tell.

37 Walter L. Newton  Thu, Jul 24, 2008 5:55:19pm

re: #33 LEGION

Where is it coming from? China or Russia? Or another bad actor. Kids from the Philippines? So dumb.

I think it was created by some disgruntled RPG III programmers.

/geek joke

38 Racer X  Thu, Jul 24, 2008 5:55:29pm

Jury Duty Scam

This has been verified by the FBI (their link is also included below). Please pass this on to everyone in your email address book. It is spreading fast so be prepared should you get this call. Most of us take those summonses for jury duty seriously, but enough people skip out on their civic duty, that a new and ominous kind of fraud has surfaced.

The caller claims to be a jury coordinator. If you protest that you never received a summons for jury duty, the scammer asks you for your Social Security number and date of birth so he or she can verify the information and cancel the arrest warrant. Give out any of this i nformation and bingo; your identity was just stolen.

The fraud has been reported so far in 11 states, including Oklahoma , Illinois , and Colorado . This (swindle) is particularly insidious because they use intimidation over the phone to try to bully people into giving information by pretending they are with the court system. The FBI and the federal court system have issued nationwide alerts on their web sites, warning consumers about the fraud.

Check it out here: [Link: www.fbi.gov...]


And here: [Link: www.snopes.com...]

39 grumpy_old_soldier  Thu, Jul 24, 2008 5:55:58pm

Oh, the thrill of the chase...this is why I am in IT.

40 sngnsgt  Thu, Jul 24, 2008 5:56:30pm

All your DNS servers are belong to us!

41 Walter L. Newton  Thu, Jul 24, 2008 5:56:54pm

re: #35 Dolphin

Question - if I VPN'ed into work and logged onto my computer there and ran the test would it detect the servers at work or my home ISP. If this does not make any sense, then this is really over my head.

At home. It would check the NAME SERVER that your home computer is connected to.

Your home computer goes to YOUR ISP name server, then to your workstation through your work network.

42 Bob in Breckenridge  Thu, Jul 24, 2008 5:58:10pm

sorrry to go O/T so soon, but I finally watched and heard all of the Obamessiah's speech from this afternoon, and, you know, as I was watching him, I was getting so pissed at that asshole.

The POS is in fuckin’ GERMANY apologizing for what we’ve done? To fuckin’ Germany?

A country that started both world wars, and is responsible for hundreds of millions of deaths around the world, including my Grandfather’s, not to mention the attempted extermination of every Jew in Europe (and on the planet if they could have) and 7 million others they deemed “undesirables”- Homosexuals, the mentally retarded and mentally and physically handicapped, gypsies, people who tried to help the Jews, and all those determined to be enemies of the Third Reich.

AND HE’S APOLOGIZING TO GERMANY FOR WHAT WE’VE DONE?

This piece of shit’s hubris, conceit, and narcissism is absolutely breathtaking.

The only reason the world is and has been relatively peaceful (with a few exceptions) for the past 60+ years and Germany (and Japan) is now rebuilt to a world power and one country with no wall separating east and west is because of the American military’s courage, guts, and blood and America’s money and our American dream and belief in freedom and democracy for all the peoples of the world.

And he’s in Germany apologizing for what we’ve done? I was friggin’ stunned as I was listening to this fucking asshole.

Then he cancels his trip to the American Military hospital at Rammstein AFB, where our troops wounded in Iraq and Afghanistan are being treated and recuperating, so he can to do some sight-seeing and shopping in friggin’ BERLIN?

He can apologize to all these Germans for all our “wrongs”, but can’t take the time to visit our wounded Soldiers, Sailors, Airmen, and Marines?

And this POS wants to be Commander-in-Chief of our armed forces?

He’s also already putting together his Presidential “transition team” for the smooth transfer of power, headed by former Clinton chief of staff/political hack John Podesta!

I guess I missed the vote, and you all did too. I thought it was on November 5th.

Can you believe the utter conceit of this piece of shit, the Obamessiah, and the outright contempt he obviously has for our country? How the hell any American can even consider voting for this asshole is astounding.

Then there's his friendships with America-hating pieces of shit like William Ayers. who with his wife bombed the Pentagon and New York Police headquarters, among other places, and who said on 9-11-01 that he didn't do enough, and was just on the cover of Chicago Magazine standing on the American flag, and his America-hating bigoted preacher of 20+ years, Jeremiah Wright.

How the hell any American can even consider voting for this asshole is astounding.

But, of course, William Ayers and his wife got jobs in the only place where hatred of America is alive, thriving, and celebrated- They're college professors.

43 Dolphin  Thu, Jul 24, 2008 5:58:46pm

re: #41 Walter L. Newton

Ok thanks. Then I cannot check the service at work from here. That's what I was wondering.

I have checked mine here at home. Comcast Houston is safe.

44 Walter L. Newton  Thu, Jul 24, 2008 5:58:55pm

re: #42 Bob in Breckenridge

Tell us how you really feel, don't hold back.

45 EC Marm  Thu, Jul 24, 2008 5:59:33pm

re: #38 Racer X
Another reason to have a cell phone only* and take the land line and pitch it in the trash can.

* And guard the number with your life.

46 TheMatrix31  Thu, Jul 24, 2008 5:59:55pm

How will we know when this issue is fixed?

47 LEGION  Thu, Jul 24, 2008 6:00:00pm

re: #38 Racer X

Well I'm safe- just had jury duty 2 months ago.

48 Walter L. Newton  Thu, Jul 24, 2008 6:00:48pm

re: #43 Dolphin

Ok thanks. Then I cannot check the service at work from here. That's what I was wondering.

I have checked mine here at home. Comcast Houston is safe.

I'm on comcast in Golden, Colorado. I check this two weeks ago when I heard about this. They have been patched since around July 8th.

Make sure you have installed any Microsoft updates that may have been pushed to your desktop. From what I have read, there is some new security stuff that works hand in hand with the DNS server patches.

49 EC Marm  Thu, Jul 24, 2008 6:00:57pm

re: #42 Bob in Breckenridge
After you wrote all that a +1 seems pretty lame. I feel your pain.

50 sngnsgt  Thu, Jul 24, 2008 6:01:24pm

re: #42 Bob in Breckenridge

Tell us how you really feel Bob...

51 LEGION  Thu, Jul 24, 2008 6:01:27pm

re: #42 Bob in Breckenridge

Osama Obama. He is evil.

52 Racer X  Thu, Jul 24, 2008 6:03:50pm

re: #42 Bob in Breckenridge

Don't stop. Let it out.

53 Dolphin  Thu, Jul 24, 2008 6:03:59pm

re: #48 Walter L. Newton

Thanks, will do.

Logging off for the night to go check computers (all five in the house)and relax for the rest of the evening.

Night all. Stay safe.

54 sngnsgt  Thu, Jul 24, 2008 6:04:09pm

Bob,

+1 from me too BTW

55 hermeneutics  Thu, Jul 24, 2008 6:04:28pm

re: #42 Bob in Breckenridge

Go Bob!

56 nyc redneck  Thu, Jul 24, 2008 6:06:14pm

re: #42 Bob in Breckenridge

great summation of the obamessiah's negatives.

57 Walter L. Newton  Thu, Jul 24, 2008 6:06:43pm

re: #42 Bob in Breckenridge

Bob, are you getting any rain up there? Every day, we get these wonderful fronts of clouds coming from your direction, and then they just sit here and do nothing. It's getting awful dry around here.

58 Thanos  Thu, Jul 24, 2008 6:06:59pm

Thanks for the opendns link, my ISP is vulnerable, but even if it's not infected with the cache thing, I think that doubleclick and other ad sites are. Some pages are clocking a full minute to load the ads after the site loads. Suspicious.

59 nacazo  Thu, Jul 24, 2008 6:07:21pm

The web site you're visiting is a clone provided to you by the Islamic Republic of Iran.

/just feeding the paranoia

60 EC Marm  Thu, Jul 24, 2008 6:07:40pm

re: #42 Bob in Breckenridge
Check this out, you might want to add it to your rant. Some comments at blogs are already saying that muslims do not celebrate birthdays or Christmas.
This is not going to win Obama any votes. I think it's going to drive another wedge between his candidacy and 75% of Americans.

61 OldLineTexan  Thu, Jul 24, 2008 6:08:58pm

re: #60 EC Marm

Check this out, you might want to add it to your rant. Some comments at blogs are already saying that muslims do not celebrate birthdays or Christmas.
This is not going to win Obama any votes. I think it's going to drive another wedge between his candidacy and 75% of Americans.

Well, Muslims celebrating Christmas would be just silly.

Jehovah's Witnesses do not celebrate Christmas or birthdays, either.

62 FishFearMe  Thu, Jul 24, 2008 6:09:07pm

re: #42 Bob in Breckenridge

Bob...Outstanding post. I logged in just to upding it.

63 offendi  Thu, Jul 24, 2008 6:09:15pm

What is interesting to me is that you always read in the general media about Chinese "hackers" attacking U.S. government sites, essentially probing the weaknesses of them, we have not seen one word about events of this nature with those in Iran.

The absence gives me a feeling that quite a lot will be going on if the Iranian nuclear sites are attacked.

64 Walter L. Newton  Thu, Jul 24, 2008 6:09:18pm

re: #58 Thanos

Thanks for the opendns link, my ISP is vulnerable, but even if it's not infected with the cache thing, I think that doubleclick and other ad sites are. Some pages are clocking a full minute to load the ads after the site loads. Suspicious.

I've notice that the "ad" links imbedded in websites have been acting funky for a number of weeks. Slow page loads, hung up getting an ad. No page loads becuase an ad never comes in (and no timeout on the ad grab code), and once in a while EI7 pops up a message saying an ad site is trying to access a DLL on my system.

65 nacazo  Thu, Jul 24, 2008 6:10:13pm

re: #42 Bob in Breckenridge

Just say: Heil Obama!

See you at the next mass rally of the National Obamist Party .

66 Lucius Septimius  Thu, Jul 24, 2008 6:10:19pm

re: #42 Bob in Breckenridge


Shelby Steele had a good piece in the WSJ earlier this week on the Obama problem. According to Steele what Jesse Jackson hates about Obama is that while the former has used White Guilt as his path to power, Obama's path involves offering to let whites "off the hook." IN other words, in the hotly contested battle for leadership, a new race card has been introduced, a sort of "absolution from all your White Guilt" "Get out of Racial Jail Free" card. The price? Elect me.

This is appealing, not just to Whites but to Blacks as well. The old racial rhetoric always presentd blacks as being deficient -- otherwise they wouldn't need programs to "raise" them up, to "level" the playing field, etc. Obama (or his handlers) realize that they can attract blacks by saying "you CAN make it on your own, you don't need anyone's help." And it is also attractive to other minorities.

Steele notes that this is a cultural issue -- Obama's appeal is rooted in the way in which his election is presented as something which will fundamentally alter racial politics, and hence American culture. THIS is the "change" he offers.

Of course, as Steele notes, there is more to being president than being a cultural symbol. In fact, the work-a-day tasks of the presidency have nothing to do with culture at all. They have to do with hard and fast issues, and on these, in no way shape or form can Obama compete with McCain. The latter is at a disadvantage on the culture side, but, Steele believes, as the campaign moves forward, Obama's difficulty to talk meaningfully about issues will be his downfall, despite the cultural appeal.

67 Walter L. Newton  Thu, Jul 24, 2008 6:10:39pm

re: #58 Thanos

Thanks for the opendns link, my ISP is vulnerable, but even if it's not infected with the cache thing, I think that doubleclick and other ad sites are. Some pages are clocking a full minute to load the ads after the site loads. Suspicious.


One more point. That DLL that the ad site wants to access IS a ligit Microsoft DLL. It's not a trojen.

68 Thanos  Thu, Jul 24, 2008 6:10:50pm

re: #61 OldLineTexan

Well, Muslims celebrating Christmas would be just silly.

Jehovah's Witnesses do not celebrate Christmas or birthdays, either.

"Issus" is a prophet according to them, just not resurrected, or the son of G-D.

69 Thanos  Thu, Jul 24, 2008 6:11:35pm

re: #64 Walter L. Newton

I've notice that the "ad" links imbedded in websites have been acting funky for a number of weeks. Slow page loads, hung up getting an ad. No page loads becuase an ad never comes in (and no timeout on the ad grab code), and once in a while EI7 pops up a message saying an ad site is trying to access a DLL on my system.

Well I sure haven't had the DLL thing, but the slow loads yes. Is your ISP RR?

70 OldLineTexan  Thu, Jul 24, 2008 6:12:38pm

re: #68 Thanos

"Issus" is a prophet according to them, just not resurrected, or the son of G-D.

Exactly. The virgin birth is OK by them, but no Holy Spirit and certainly no Trinity.

71 Walter L. Newton  Thu, Jul 24, 2008 6:12:45pm

re: #69 Thanos

Well I sure haven't had the DLL thing, but the slow loads yes. Is your ISP RR?

No, Comcast. What's RR? Aren't you across the pond?

72 EC Marm  Thu, Jul 24, 2008 6:13:46pm

re: #61 OldLineTexan

Well, Muslims celebrating Christmas would be just silly.

Jehovah's Witnesses do not celebrate Christmas or birthdays, either.


But Obama is trying to shake the 10 to 20 per cent of Americans that think he is muslim. I've yet to hear that he spent any time in a JW madrassa in Indonesia. :~)

73 sngnsgt  Thu, Jul 24, 2008 6:15:35pm

re: #71 Walter L. Newton

Roadrunner?

74 Walter L. Newton  Thu, Jul 24, 2008 6:15:37pm

Excuse all, my spelling stinks tonight.

75 Walter L. Newton  Thu, Jul 24, 2008 6:16:18pm

re: #73 sngnsgt

Roadrunner?

No, I'm part German!

76 Slumbering Behemoth  Thu, Jul 24, 2008 6:16:46pm

Soooo.....

How reliable/credible is this OpenDNS I keep hearing about?

77 sngnsgt  Thu, Jul 24, 2008 6:17:31pm

re: #75 Walter L. Newton

lol, you know what I meant... ;-)

78 Big Steve  Thu, Jul 24, 2008 6:18:41pm

Does anyone have a link where I can read Obama's Germany speech?

79 CyanSnowHawk  Thu, Jul 24, 2008 6:19:35pm

re: #66 Lucius Septimius

I read that. It was pretty good, and really points out the difference between BHO and The Rev. BHO is a different animal, and one that should have come along many years ago, at least in terms of race relations. Perhaps BHO will be the example that the left needs to show the heights you can attain by staying away from the 'I'm a victim' button. We would be in real trouble if this guy had any substance to back up his style.

80 Walter L. Newton  Thu, Jul 24, 2008 6:20:06pm

re: #78 Big Steve

Does anyone have a link where I can read Obama's Germany speech?

[Link: elections.foxnews.com...]

81 sngnsgt  Thu, Jul 24, 2008 6:20:17pm

re: #78 Big Steve

Drudge transcript

82 HoosierHoops  Thu, Jul 24, 2008 6:20:21pm

re: #76 Slumbering Behemoth

Soooo.....

How reliable/credible is this OpenDNS I keep hearing about?


Yea..we are going to open our DNS tables to the world..
Not..
/hey folks...whats up?

83 Lucius Septimius  Thu, Jul 24, 2008 6:20:29pm

re: #79 CyanSnowHawk

We would be in real trouble if this guy had any substance to back up his style.

Well, no danger of that, I daresay.

84 MadNachos  Thu, Jul 24, 2008 6:20:37pm

re: #76 Slumbering Behemoth

Soooo.....

How reliable/credible is this OpenDNS I keep hearing about?

Very/very.

Its a good service and well worth checking into. Their DNS servers are quite fast due to the massive cache they run.

85 Cartman  Thu, Jul 24, 2008 6:20:39pm
On Monday, security company Matasano accidentally posted details of the flaw on its Web site. Matasano quickly removed the post and apologized for its mistake, but it was too late. Details of the flaw soon spread around the Internet.

Ooops.

86 Walter L. Newton  Thu, Jul 24, 2008 6:20:49pm

re: #77 sngnsgt

lol, you know what I meant... ;-)

Oh... the other half is French.

87 sngnsgt  Thu, Jul 24, 2008 6:21:49pm

re: #86 Walter L. Newton

Oh... the other half is French.

Wee, wee...

88 Cartman  Thu, Jul 24, 2008 6:22:09pm

re: #78 Big Steve

Does anyone have a link where I can read Obama's Germany speech?

Nickelodeon.

89 The Shadow Do  Thu, Jul 24, 2008 6:22:36pm

re: #42 Bob in Breckenridge

sorrry to go O/T so soon, but I finally watched and heard all of the Obamessiah's speech from this afternoon, and, you know, as I was watching him, I was getting so pissed at that asshole.

The POS is in fuckin’ GERMANY apologizing for what we’ve done? To fuckin’ Germany?

A country that started both world wars, and is responsible for hundreds of millions of deaths around the world, including my Grandfather’s, not to mention the attempted extermination of every Jew in Europe (and on the planet if they could have) and 7 million others they deemed “undesirables”- Homosexuals, the mentally retarded and mentally and physically handicapped, gypsies, people who tried to help the Jews, and all those determined to be enemies of the Third Reich.

AND HE’S APOLOGIZING TO GERMANY FOR WHAT WE’VE DONE?

This piece of shit’s hubris, conceit, and narcissism is absolutely breathtaking.

The only reason the world is and has been relatively peaceful (with a few exceptions) for the past 60+ years and Germany (and Japan) is now rebuilt to a world power and one country with no wall separating east and west is because of the American military’s courage, guts, and blood and America’s money and our American dream and belief in freedom and democracy for all the peoples of the world.

And he’s in Germany apologizing for what we’ve done? I was friggin’ stunned as I was listening to this fucking asshole.

Then he cancels his trip to the American Military hospital at Rammstein AFB, where our troops wounded in Iraq and Afghanistan are being treated and recuperating, so he can to do some sight-seeing and shopping in friggin’ BERLIN?

He can apologize to all these Germans for all our “wrongs”, but can’t take the time to visit our wounded Soldiers, Sailors, Airmen, and Marines?

And this POS wants to be Commander-in-Chief of our armed forces?

He’s also already putting together his Presidential “transition team” for the smooth transfer of power, headed by former Clinton chief of staff/political hack John Podesta!

I guess I missed the vote, and you all did too. I thought it was on November 5th.

Can you believe the utter conceit of this piece of shit, the Obamessiah, and the outright contempt he obviously has for our country? How the hell any American can even consider voting for this asshole is astounding.

Then there's his friendships with America-hating pieces of shit like William Ayers. who with his wife bombed the Pentagon and New York Police headquarters, among other places, and who said on 9-11-01 that he didn't do enough, and was just on the cover of Chicago Magazine standing on the American flag, and his America-hating bigoted preacher of 20+ years, Jeremiah Wright.

How the hell any American can even consider voting for this asshole is astounding.

But, of course, William Ayers and his wife got jobs in the only place where hatred of America is alive, thriving, and celebrated- They're college professors.

Thanks, Bob. You blew your cork so I didn't have to. We are the change we have been waiting for, yes?

90 nyc redneck  Thu, Jul 24, 2008 6:22:38pm

b.o. says they don't celebrate christmas or birthdays w/ gifts because they have to ' teach their daughters limits'.
that's just weird.
but they want to deprive us too.
no heat, no a.c., no eating all we want. that's the way he rolls.
wonder if he is going to outlaw gift giving because the rest of the world may not be ok w/ that..

91 Walter L. Newton  Thu, Jul 24, 2008 6:23:22pm

re: #87 sngnsgt

Wee, wee...

Oui, Oui, get with the program :) Most here know this, but France is my favorite place in Western Europe. So sue me!

92 Slumbering Behemoth  Thu, Jul 24, 2008 6:23:47pm

re: #82 HoosierHoops

Yea..we are going to open our DNS tables to the world..
Not..

What? That went over my head.

93 offendi  Thu, Jul 24, 2008 6:24:24pm

re: #42 Bob in Breckenridge

Obama is the shiny new car that every half-wit wants because it looks good on the surface, but has substandard mechanics and faulty systems.

While media people make much of racism arising from Obama running for President they conveniently overlook the fact that a similarly experienced "typical white" politician would never have gotten to this point so far, fast, and without extreme vetting. Without his half-African-Americaness Obama would be just another junior senator who speaks well.

His positions reflect an arrogance untempered by experience that will get him in major trouble in dealing with people who don't also believe in spinning words, but taking action, like muslim fanatics. With his education he will be too busy trying to analyze and understand their grievances, instead of taking proactive steps for our security.

While John McCain is certainly no prize, you have to believe he is not going to get us into a deadly world situation from conceit, arrogance, and over self-estimation. This guy Obama however, will.

94 TheMatrix31  Thu, Jul 24, 2008 6:24:50pm

Just called Time Warner (I live in LA), the person (who barely spoke English) gave me some long winded, plastic answer. I guess the jist of it is that they're working on resolving the issue, so I don't know where that leaves me. I asked her if it was safe to do banking/shopping and she said it was. She said something about July 24th, I think saying that they were patching it up today or something.

So unclear.

95 Pvt Bin Jammin  Thu, Jul 24, 2008 6:25:27pm

My server seems to be safe but how in the heck do you check to see if the ports mentioned are following a suspicious pattern?

96 buzzsawmonkey[deleted]  Thu, Jul 24, 2008 6:25:41pm
97 sngnsgt  Thu, Jul 24, 2008 6:26:01pm

re: #91 Walter L. Newton

Oui, Oui, get with the program :) Most here know this, but France is my favorite place in Western Europe. So sue me!

My Wee, Oui, has a different meaning, I was thinking about the Obamessiah when I typed that.

98 Walter L. Newton  Thu, Jul 24, 2008 6:26:53pm

re: #95 Pvt Bin Jammin

My server seems to be safe but how in the heck do you check to see if the ports mentioned are following a suspicious pattern?

You can't. Those are ports on the DNS server. You may want to inform your ISP, although if they did patch, then they are probably aware of the possible vunerable ports.

They would have to look at their logs to see a pattern.

99 Slumbering Behemoth  Thu, Jul 24, 2008 6:27:39pm

re: #84 MadNachos

Very/very.

Its a good service and well worth checking into. Their DNS servers are quite fast due to the massive cache they run.

It appears I must do some research on this topic.

100 Pvt Bin Jammin  Thu, Jul 24, 2008 6:27:48pm

re: #98 Walter L. Newton
Thanks, I am so non technical.

101 Kosh's Shadow  Thu, Jul 24, 2008 6:27:52pm

To avoid phishing, I view the source of any email to look at the links.
I'll report ones that look phishy like
[Link: www.bigbank.com.hackers.za...]
when I want to get to bigbank.com

What this attack does is mean that I could type in bigbank.com and it would still give me the server in Zambia. (I use za because my wife got a couple of them from there; she asks me and I tell her that it is phishing, before she gets hooked.)

Anyway, I wanted to give my gripe that vendors seem to be taking away the ability to view the source of a message before it is opened. Microsoft hides the view source, and you have to have opened it first, hoping that the Microsoft product wasn't vulnerable to something in the email.
Apple Mail also requires you to have opened the email first.
Verizon webmail lets me view source, but it still previews the message; not great, but with noscript, I am probably safe. (I like seeing the phishing in its spam filter. Boy, people are stupid. The Nigerian email scam is going strong - and plainly says it is from Nigeria! Some people, as Dogbert says, are too stupid to use a computer)
Firefox, though, does let me view source without opening the message, which is one reason I use it.

102 EC Marm  Thu, Jul 24, 2008 6:28:55pm

re: #96 buzzsawmonkey
A question for you. Just how far out of the mainstream do you think it is for a Presidential candidate to not give presents on either his children's birthdays, or one of the most important days of his *cough* religion?

103 OldLineTexan  Thu, Jul 24, 2008 6:29:17pm

re: #95 Pvt Bin Jammin

My server seems to be safe but how in the heck do you check to see if the ports mentioned are following a suspicious pattern?

Do they leave work early, but not go home?
Have they opened single-card credit accounts, even though they are married?
Do they spend a lot of time alone?
Have they changed friends?

/////

104 Pvt Bin Jammin  Thu, Jul 24, 2008 6:30:09pm

re: #103 OldLineTexan
LOL

105 sparrowlake  Thu, Jul 24, 2008 6:31:10pm

re: #42 Bob in Breckenridge

The only reason the world is and has been relatively peaceful (with a few exceptions) for the past 60+ years and Germany (and Japan) is now rebuilt to a world power and one country with no wall separating east and west is because of the American military’s courage, guts, and blood and America’s money and our American dream and belief in freedom and democracy for all the peoples of the world.

Great post, and very well said.
America's military and middle class bleeds into the rug while countries around the world smugly take cheap pot shots at their American benefactors and artfully withhold their support. And this master of guilt-trips and self-deception, this cowardly creep, adding insult to injury with his orgy of self flagellation - travels around from sound bite to photo op, like a stinking fart trapped in his own colon.

106 Lucius Septimius  Thu, Jul 24, 2008 6:31:21pm

re: #96 buzzsawmonkey

But to have "substance" he would have to not be in bed with as many radicals and racists as he is; he would have to have a record of achievement; he would have to have a clue about history; he would have to have a view of economics which was not so close to crackpot.

Ay, there's the rub, isn't it?

The lame, predictable anti-American tenor of his speech reveals how deeply in bed with the radicals he is, despite all of his efforts to present himself as some sort of "pragmatist."

Either he's a hard Leftist or a cynical poser. Neither is a good resume builder for president.

As far as the rest of it, he's amazingly poorly educated except in rhetoric.

107 sngnsgt  Thu, Jul 24, 2008 6:31:27pm

re: #104 Pvt Bin Jammin

Guilty, I LOL too!

108 HoosierHoops  Thu, Jul 24, 2008 6:33:14pm

re: #92 Slumbering Behemoth

What? That went over my head.

Sorry bro... I jumped into the middle of a discussion..
DNS tables unique to each company allow access to each domains servers via a naming convention..these are kept secret within each private network..ie 10.x.x.x. we advertise on the internet via an external interface..No one would allow DNS within in open system
an access..You don't get in..
does that make sense?

109 nacazo  Thu, Jul 24, 2008 6:33:26pm

re: #102 EC Marm

A question for you. Just how far out of the mainstream do you think it is for a Presidential candidate to not give presents on either his children's birthdays, or one of the most important days of his *cough* religion?

Not as important as lying their way into power. Saying the opposite views on an issue to different audiences on the same week. Fomenting the cult of personality to attain power. Using ex-terrorists, black supremacists, corrupt Real Estate brokers and throwing them under the bus while pretending to be ultra clean above politics.

110 Big Steve  Thu, Jul 24, 2008 6:34:44pm

Since this thread is all over the place, I did go and read Obama's speech (thanks for the link Lizards). I was puzzled by the quote:

In Europe, the view that America is part of what has gone wrong in our world, rather than a force to help us make it right, has become all too common. In America, there are voices that deride and deny the importance of Europe’s role in our security and our future.

The cadence is funny. It starts with sort of an empathetic comment about EU's view of America but ends with using "deride" in the American view of EU. Deride is a more evocative word. In fact if he had left it out and just said, "there are voices that deny the importance of Europe's...." it would have balanced more. This to me is very telling and seems to indicate sympathy with the EU view. I realize he was in Germany but this struck me as odd.

Several others have pointed out issues with the speech. However I must say (oh the horror) that most of the speech wasn't half bad.

111 Lucius Septimius  Thu, Jul 24, 2008 6:35:32pm

re: #105 sparrowlake

Great post, and very well said.
America's military and middle class bleeds into the rug while countries around the world smugly take cheap pot shots at their American benefactors and artfully withhold their support. And this master of guilt-trips and self-deception, this cowardly creep, adding insult to injury with his orgy of self flagellation - travels around from sound bite to photo op, like a stinking fart trapped in his own colon.

The Times of London had a great piece on the Obamaphenoma, basically that anti-Americanisn is unavoidable because America rocks, and the Eu-niks who looooooove Obamamama now will hate him too precisely because he's an American.

112 Slumbering Behemoth  Thu, Jul 24, 2008 6:39:31pm

re: #108 HoosierHoops

Sorry bro... I jumped into the middle of a discussion..
DNS tables unique to each company allow access to each domains servers via a naming convention..these are kept secret within each private network..ie 10.x.x.x. we advertise on the internet via an external interface..No one would allow DNS within in open system
an access..You don't get in..
does that make sense?

Well, yes and no. No because I was asking about a specific service called "OpenDNS", where rather than using your ISP's DNS servers you use those of "OpenDNS", which I have heard been touted as being more secure than the ISP's servers.

I'm just wondering how much truth there is to these claims, and what else there might worth knowing about the "OpenDNS" service.

113 EC Marm  Thu, Jul 24, 2008 6:42:07pm

re: #109 nacazo

Not as important as lying their way into power. Saying the opposite views on an issue to different audiences on the same week. Fomenting the cult of personality to attain power. Using ex-terrorists, black supremacists, corrupt Real Estate brokers and throwing them under the bus while pretending to be ultra clean above politics.


All true to us hard-core political junkies that follow the breaking news by the minute. But to John and Jane Doe of America, 75% or more of whom are Christian, I guarantee you this is going to shake them out of their sleep and say, "What the hell? Maybe he is a Muslim."
It is already the most searched for phrase on my little blog.

114 buzzsawmonkey[deleted]  Thu, Jul 24, 2008 6:54:17pm
115 buzzsawmonkey[deleted]  Thu, Jul 24, 2008 6:55:33pm
116 Lucius Septimius  Thu, Jul 24, 2008 7:00:15pm

re: #115 buzzsawmonkey

He's a rube with a thin, cheap, shiny gloss of what passes for education these days.

It'll wear off in your pocket in a hurry.

117 Lucius Septimius  Thu, Jul 24, 2008 7:01:41pm

re: #115 buzzsawmonkey

How ya doin, btw?

118 EC Marm  Thu, Jul 24, 2008 7:03:16pm

re: #114 buzzsawmonkey

I've never heard of this. And I have to sign off in about two seconds. Explain/amplify, and I'll check it out tomorrow.


[Link: www.politico.com...]
You can catch up to me later with thoughts.

119 zerodamage  Thu, Jul 24, 2008 7:05:07pm

This is an easy thing to fix on your home machine. Use OpenDNS.com for your DNS servers. You do not have to sign up to use them. Just change your routers or your computer's DNS servers and you are good to go.

120 MadNachos  Thu, Jul 24, 2008 7:29:27pm

re: #112 Slumbering Behemoth
I'm just wondering how much truth there is to these claims, and what else there might worth knowing about the "OpenDNS" service.

I have been a UNIX and Bind admin for many years (UNIX for 20, Bind about 10)...not sure what you are worried about by querying OpenDNS' servers vs. your own or your ISP's DNS servers. By nature the data transfered back and forth while performing DNS lookups is un-encrypted and open to sniffing, and even if someone could figure out what queries you are performing...what good would that do them? Even if someone could figure out what address range your internal addresses used it would not do them any good if you had a reasonable level of security for your enterprise. In fact, it should be no threat at all....security through obscurity is not security at all...

If you are concerned with showing your hand when it comes to your internal network IP addressing scheme you can simply configure your DNS servers to use your own DNS servers for your domain(s)..internal or otherwise..and have your DNS servers forward external DNS lookups to OpenDNS. No harm, no foul...after all...when you query any external domain you are using external servers anyway, at least until your local servers cache the information.

Check out OpenDNS, open a account there, and I think you will grow to find it a very useful service....especially if you use the filtering options they provide.

121 Slumbering Behemoth  Thu, Jul 24, 2008 7:37:56pm

re: #120 MadNachos

Not worried, just ignorant on many aspects of this subject. Thanks for the response.

122 Bob in Breckenridge  Thu, Jul 24, 2008 7:50:42pm

re: #93 offendi

Obama is the shiny new car that every half-wit wants because it looks good on the surface, but has substandard mechanics and faulty systems.

While media people make much of racism arising from Obama running for President they conveniently overlook the fact that a similarly experienced "typical white" politician would never have gotten to this point so far, fast, and without extreme vetting. Without his half-African-Americaness Obama would be just another junior senator who speaks well.

His positions reflect an arrogance untempered by experience that will get him in major trouble in dealing with people who don't also believe in spinning words, but taking action, like muslim fanatics. With his education he will be too busy trying to analyze and understand their grievances, instead of taking proactive steps for our security.

While John McCain is certainly no prize, you have to believe he is not going to get us into a deadly world situation from conceit, arrogance, and over self-estimation. This guy Obama however, will.

So Obama's like a DeLorean, huh? Back to the future!

123 savarulz  Thu, Jul 24, 2008 7:59:46pm

thank you charles for the heads up and the quick link to check my computer

124 MadNachos  Thu, Jul 24, 2008 8:08:42pm

re: #121 Slumbering Behemoth

You are right to be worried...that is the key to keeping things secure. More people should be worried about security ;-)

I did a lot of D.D. on OpenDNS a while back when we were considering using it for a few locations and its a pretty stand-up company. I trust 'em, if you check them out and use their service on a test basis on a few machines you will probably come to trust them too.

Frankly, once I figured out how they make money I was a lot less worried. That was the on thing that bothered me right off: How do they make money? Well...they make money by using targeted adverts (like google does) when someone attempts to lookup a bad or blocked address that show up on their 'your admin blocked access to this site / the address you are looking up is not valid' pages. Interesting angle.

125 Dasher  Thu, Jul 24, 2008 8:19:50pm

re: #42 Bob in Breckenridge

Bob -- Tell us what you really think about that POS Obama.

126 phaneul  Thu, Jul 24, 2008 8:22:21pm

I just checked Kaminsky's site through the posted link and it's down now. Either he's updating or he got bit. Thanks for the heads-up.

127 jcw46  Thu, Jul 24, 2008 11:00:10pm

just emailed kaminsky about this:
if you use comcast and use the dns patch detector, you may get knocked offline. I have comcast and when i used the detector i got knocked offline and it took 2 reboots of the router/modem and some fingernail chewing minutes till I was back online.

Just thought i'd mention it.

128 Ledger1  Fri, Jul 25, 2008 1:44:36am

The exploit seems to involve the RCP and dynamic updating of DNS in active directory. Also, there is still some indication that Kaminsky’s DNS bug is in the wild and he may have had a part in writing it according to The register (that is just speculation of course).


see Exploit code for Kaminsky DNS bug

[Link: www.caughq.org...]
loits/CAU-EX-2008-0003.txt
Also see DNS exploit tool credits
link deliberately broken as to not spread the code.

129 ebed_melech  Fri, Jul 25, 2008 6:00:19am

Thank you Charles - we too have been vulnerable.

A general question, how safe is the firefox browser for the non technical?

130 buzzsawmonkey[deleted]  Fri, Jul 25, 2008 7:13:05am
131 panamahat  Fri, Jul 25, 2008 11:07:01pm

Thanks a lot, Charles. I saw this somewhere else but it was written for geeks so I passed over it. Between you and Dan Kaminsky, I now understand and have one less thing to worry about.


This entry has been archived.
Comments are closed.

^ back to top ^

log in
Name:
Pass:

Register Forgot Your Password? My Account Re-send Confirmation (To log in, cookies must be enabled in your browser!)

► LGF Headlines

► Top 10 Comments

► Bottom Comments

► Recent Comments

► Tools/Info

► LGF Hits

► Slideshows

► Resources

► Never Forget

► Statistics

► Tag Cloud

► Contact

You must have Javascript enabled to use the contact form.
Your email:

Subject:

Message:


Messages may be published in our weblog, unless you request otherwise.
Tech Note:
Using the Contact Form

► News/Opinion

More Partners

Compare Electricity Prices in your area. Texas Electricity is deregulated; you have the right to choose Texas Electric Rates from among many Texas Electric Companies.

Now, nobody dance!


Barnes & Noble Home