You are currently unregistered, register for more features.    
 
Home Forums     AO Club Member Gallery
Register FAQ Members Calendar
Mark Forums Read
Welcome Guest
Go Back  Alfa Romeo Forum > Misc Lounges > Community Discussions > Way Off Topic
Mark Forums Read

Sign Up Today!
Reply
 
Thread Tools
Old 27-07-2008   #26 (Post Link)
Regional Representative
For Wales South - AOWS
 
alfa-female's Avatar
 
Join Date: Apr 2008
Location: Usk,south wales
Posts: 6,985
Re: Computer Test - Well Worth Trying...

194.74.65.68 (ns6.bt.net) appears to have POOR source port randomness and GREAT transaction ID randomness.
194.72.0.98 (indnsc60.ukcore.bt.net) appears to have POOR source port randomness and GREAT transaction ID randomness.





what thre hell have i just tested my comp for?
alfa-female is offline  
Digg this Post!Add Post to del.icio.usFurl this Post!
Reply With Quote
Old 27-07-2008   #27 (Post Link)
Club Member
Membro Premio
 
scsc's Avatar
 
Club Member Number: 442
Join Date: Apr 2008
Location: Linlithgow
Posts: 757

Member car:

Spider 2.4 JTDM

Re: Computer Test - Well Worth Trying...

Originally Posted by mikeruss View Post
The solution to the poor and bad ;-)

OpenDNS | Providing A Safer And Faster Internet

Plus you'll web browsing will be faster, aaand if your kid is looking at naked ladies you can block it.
I'm still baffled......
scsc is offline  
Digg this Post!Add Post to del.icio.usFurl this Post!
Reply With Quote
Old 27-07-2008   #28 (Post Link)
Regional Representative
For Wales South - AOWS
 
alfa-female's Avatar
 
Join Date: Apr 2008
Location: Usk,south wales
Posts: 6,985
Re: Computer Test - Well Worth Trying...

baffled twice over me
alfa-female is offline  
Digg this Post!Add Post to del.icio.usFurl this Post!
Reply With Quote
Old 27-07-2008   #29 (Post Link)
Regional Representative
For East Anglia - AOEA
 
PaulR's Avatar
 
Join Date: Mar 2005
Location: United Kingdom
Posts: 7,504
Re: Computer Test - Well Worth Trying...

Strange thing - no matter what the result your computer seems to carry on working with no discernable difference.

An old fart speaks.

Paul.
PaulR is offline  
Digg this Post!Add Post to del.icio.usFurl this Post!
Reply With Quote
Old 27-07-2008   #30 (Post Link)
Club Member
Membro Premio
 
scsc's Avatar
 
Club Member Number: 442
Join Date: Apr 2008
Location: Linlithgow
Posts: 757

Member car:

Spider 2.4 JTDM

Re: Computer Test - Well Worth Trying...

Originally Posted by PaulR View Post
Strange thing - no matter what the result your computer seems to carry on working with no discernable difference.
Until it doesn't. And that's how they scare you into spending money.

Sceptics/old farts of the world must unite to fight the tyranny of the geek.
scsc is offline  
Digg this Post!Add Post to del.icio.usFurl this Post!
Reply With Quote
Old 27-07-2008   #31 (Post Link)
Regional Representative
For East Anglia - AOEA
 
PaulR's Avatar
 
Join Date: Mar 2005
Location: United Kingdom
Posts: 7,504
Re: Computer Test - Well Worth Trying...

Originally Posted by scsc View Post
Until it doesn't. And that's how they scare you into spending money.

Sceptics/old farts of the world must unite to fight the tyranny of the geek.

We must - but, but, they come at you with their smiley faces (always rimmed by glasses) with that expression in their eyes which says:-


"I think you are a prat but I've been on a course for the socially dyslexic (me) so I can patronise you by talking fluent Geek and you must recocgnise my right to do so".

We understand nothing of "Error 404" but pretend to understand less we fail geeks right to a hearing.
PaulR is offline  
Digg this Post!Add Post to del.icio.usFurl this Post!
Reply With Quote
Old 27-07-2008   #32 (Post Link)
AO Silver Member
 
Friggertool's Avatar
 
Join Date: Feb 2007
Location: East Spiral Arm of Galaxy
Posts: 2,733

Member car:

Brera 3.2

Re: Computer Test - Well Worth Trying...

prolly just collecting addresses for spam. Surely you know if your connection works ok.
Friggertool is offline  
Digg this Post!Add Post to del.icio.usFurl this Post!
Reply With Quote
Old 27-07-2008   #33 (Post Link)
AO Member
 
Join Date: Jul 2007
Posts: 218

Member car:

GTV V6 Turbo

Re: Computer Test - Well Worth Trying...

Originally Posted by scsc View Post
Does anyone know if port randomness is terminally bad? And what we should be doing about it? Clues please vela blue.

I'd really hate to have to stop talking to you all...... Byyeeeeee
I'd like to see better source port randomness - but I'm pleased to see nobody has poor and poor ratings on the one nameserver so far. The whole exploit works by predicting what the nameserver is expecting and feeding it duff data.

Nameservers dish out the ip numbers for a web address you type into your browser - the exploit works by giving you back false numbers for that web site address that you typed in. So the page you are viewing may not be the actual genuine page.

The linux newsgroups I'm on have already seen attempts on bigger site names - Google, Facebook, etc coming through in their logs which prompted me to post my original note yesterday afternoon. I don't want to be alarmist but think people need to be made aware of their own ISP's performance.
vela blue is offline  
Digg this Post!Add Post to del.icio.usFurl this Post!
Reply With Quote
Old 27-07-2008   #34 (Post Link)
AO Member
 
Join Date: Jul 2007
Posts: 218

Member car:

GTV V6 Turbo

Re: Computer Test - Well Worth Trying...

Originally Posted by alfapersius View Post
Hi Bryan,

are you running bind at work? What version you using?
Yes we run bind version 9

I would point out that it does affect other nameserver services besides bind, so well worth checking your particular flavour of nameserver and whether there are updates available.

Full story is here: -

DoxPara Research

He discovered the problem and worked with the vendors on patching.
vela blue is offline  
Digg this Post!Add Post to del.icio.usFurl this Post!
Reply With Quote
Old 27-07-2008   #35 (Post Link)
Club Member
Membro Medio
 
Quinn's Avatar
 
Club Member Number: 57
Join Date: Jun 2003
Location: United Kingdom
Posts: 12,572
Re: Computer Test - Well Worth Trying...

I just looked over everybody's posts on this whole
thread in an attempt to figure it out, just for me own curiosity

...and...nope...not a bean

...where did the barman go ... oi
Quinn is offline  
Digg this Post!Add Post to del.icio.usFurl this Post!
Reply With Quote
Old 27-07-2008   #36 (Post Link)
AO Member
 
Join Date: Jul 2007
Posts: 218

Member car:

GTV V6 Turbo

Re: Computer Test - Well Worth Trying...

Hi Everyone

Just thought I'd post up a non-technical link to the post which is really easy to read through and get an understanding of how it works. This was done by Dan Kaminsky who discovered the exploit.

Details : DoxPara Research

and the text as below: -

I thought it would be helpful, given things going on out there, to write up a guide to the attack that people could provide to their management. A lot of people are going to have to violate procedure and work extra hours. Maybe this will get a few pizzas approved

==

DNS is a system for, among other things, finding out what number to use when “calling” somebody on the Internet. Since there’s lots of people, in lots of places, there can’t just be one directory. Often, when you ask one server for a number, it tells you to go somewhere else. And when you go there, you might be sent to a third destination. This process — “recursion” — is repeated over and over, until you finally have the number for that name.

Of course, on the Internet, you aren’t really going anywhere. What’s actually happening is that you’re sending messages out, and receiving replies back. What prevents a bad guy from providing his own replies, with his own fake numbers for whatever you were looking for?

Not much — but not nothing.

DNS can be thought of as a race: A request is sent. A good guy and a bad guy both want to get their replies to be trusted. The good guy has an advantage: He sees the request, and inside of it he can find a secret number, somewhere between zero to sixty five thousand. The race is not won until someone crosses the finish line with the secret number, and while the bad guy could guess the number, he has only a 1/65,536 chance of guessing correctly. Worse, the winner of the race gets to say how long it will be until the next race! The numbers can work out that it would take months, even years for the bad guy to finally win a race.

However, there are three problems. The first two were somewhat known. The second is very new.

First, the bad guy holds the starter pistol. He decides when the request goes out — meaning, he may not know *what* the secret number is, but he actually knows the race has started before the good guy does.

Second, the bad guy is not alone. He can have as many “runners” in the race as he likes — the race is only over when someone arrives with the correct secret number. The bad guy can try wrong number after wrong number, and until the good guy shows up with the right one, he can keep trying again and again. If he can squeeze a hundred numbers in, the odds drop from one in sixty five thousand to one in six fifty five.

But those are still long odds, and if he loses, he might have to wait a day to try again.

Or he might not.

What’s new is that the bad guy doesn’t actually have to wait to start another race. DNS is actually more of a relay race than a sprint. Remember, you send a request to a server, and you might get a reply that says “www.foobar.com? Sure, here’s the IP address to use.” Or, you might get a message that says, “www.foobar.com? I don’t know, ask ns1.foobar.com, here’s its address.” That’s recursion. It’s not a bug, or a rarely used feature. DNS is always sending you to different servers to find a record — this is how the servers that run .com work.

Now, there is a limit: Not just any other name will work — or else, I could return to you “www.foobar.com? Oh, that’s hosted at Google, and here’s its address”, and you’d believe me. (Eleven years ago, that actually worked.) But names near www.foobar.com — 1.foobar.com, 2.foobar.com, 3.foobar.com — are referred to as “in-bailiwick”. A referral to a name in-bailiwick must be trusted.

And so, the attack. If someone’s trying to attack www.foobar.com, he doesn’t pull out the starter pistol for that particular name. After all, the server might not be willing to go out looking for www.foobar.com for hours. No, he declares races for 1.foobar.com, 2.foobar.com, 3.foobar.com, and so on.

The bad guy will probably lose these races. The odds, even with a hundred-to-one advantage in the number of “runners”, are against him.

But he can run as many races as he wants. And eventually, he’ll win one of them. And when he does win — when the bad guys guesses the secret number from 0 to 65536 — he won’t just provide an answer for the random name that won. He’ll simply feign ignorance: “83.foobar.com? I don’t know, ask www.foobar.com, here’s its address. Oh, and remember this for the next week.”

He won the race. He gets his say.

Now, there have been some problematic DNS attacks in the past. Amit Klein was able to guess the secret number the good guy would return with. Joe Stewart was able to cause many secret numbers to be accepted. But neither of the attacks could override a race that had already been won. Once a name server is storing — caching — the number for a given name, it simply won’t run another race for that name. Why should it? It knows the number!

Joe’s attack needs another race for www.foobar.com. Amit’s attack needs another race for www.foobar.com.

In my attack, we never race for www.foobar.com. We race for another name entirely. It’s a problem. It required a lot of work to address.

===

Incidentally, some people wanted more details on the numbers. Here’s what I can say:

1) Sweeping the net’s open recursive name servers — yeah, that ain’t great. But if nobody’s using ‘em, nobody’s vulnerable. And if it’s an open recursive name server on the Internet, there’s a good chance nobody’s managed it for several years. I’m working on load measurement hacks for these.

2) Lots and lots of important places haven’t patched.

3) I still haven’t gotten my testing script to correctly handle iptables and pf randomization. This is getting worked on — damn you creative people and your tricks!

4) From July 8th to July 9th, 4242 of 5000 tests actively run by users behind unique name servers showed that server to be vulnerable. That’s about 85%. Today, July 25th, the last 5000 tests (about the last six hours) from unique name servers show only 2503 of 5000 vulnerable — just above 50%. Now, I’m not going to deny. There’s selection bias. It’s a limited sample. There are tons and tons of unpatched ISPs. This is all true.

You know what? A lot of people did a lot of work to make that number drop. More needs to be done, but 13 days made a difference, and it’s awesome to see it.

Last edited by vela blue : 27-07-2008 at 14:17. Reason: typo
vela blue is offline  
Digg this Post!Add Post to del.icio.usFurl this Post!
Reply With Quote
Old 27-07-2008   #37 (Post Link)
Club Member
Membro Medio
 
Quinn's Avatar
 
Club Member Number: 57
Join Date: Jun 2003
Location: United Kingdom
Posts: 12,572
Re: Computer Test - Well Worth Trying...

was pulling yer plonker Vela
Quinn is offline  
Digg this Post!Add Post to del.icio.usFurl this Post!
Reply With Quote
Old 27-07-2008   #38 (Post Link)
AO Member
 
Join Date: Jul 2007
Posts: 218

Member car:

GTV V6 Turbo

Re: Computer Test - Well Worth Trying...

Originally Posted by Quinn View Post
was pulling yer plonker Vela
Hehe that's fine Quinn, but I think other people didn't understand what the problem was and this is a fairly easy read to grasp it.
vela blue is offline  
Digg this Post!Add Post to del.icio.usFurl this Post!
Reply With Quote
Old 27-07-2008   #39 (Post Link)
Club Member
Membro Premio
 
Hammy156's Avatar
 
Club Member Number: 253
Join Date: Dec 2006
Location: United Kingdom
Posts: 11,537

Member car:

'99 vintage 156

Re: Computer Test - Well Worth Trying...

Originally Posted by vela blue View Post
Hehe that's fine Quinn, but I think other people didn't understand what the problem was and this is a fairly easy read to grasp it.
Indeed it is, thanks for posting
Hammy156 is offline  
Digg this Post!Add Post to del.icio.usFurl this Post!
Reply With Quote
Old 27-07-2008   #40 (Post Link)
Club Member
Membro Medio
 
Quinn's Avatar
 
Club Member Number: 57
Join Date: Jun 2003
Location: United Kingdom
Posts: 12,572
Re: Computer Test - Well Worth Trying...

Originally Posted by vela blue View Post
Hehe that's fine Quinn, but I think other people didn't understand what the problem was and this is a fairly easy read to grasp it.
fair enough ....all the best mate
Quinn is offline  
Digg this Post!