Re: [Full-Disclosure] rfc1918 space dns requests

Valdis.Kletnieks_at_vt.edu
Date: 03/16/04

  • Next message: martin f krafft: "[Full-Disclosure] Re: a secure base system"
    To: "Geo." <geoincidents@getinfo.org>
    Date: Tue, 16 Mar 2004 12:12:48 -0500
    
    
    

    On Tue, 16 Mar 2004 11:43:48 EST, "Geo." <geoincidents@getinfo.org> said:

    > I'm aware of the issues involved with an ISP passing the requests on to the
    > root servers but was looking specifically for security type issues relating
    > to a private network passing the requests out to their ISP's dns servers.

    There's several basic vulnerabilities here:

    1) The same screw-up that allows the DNS requests to escape can almost
    certainly be used to tunnel other stuff in/out of the network. Find ways
    to use this to your advantage.

    2) We've got applications making DNS requests that get forwarded out to
    the ISP's servers, where they will almost certainly result in either an error
    reply or a timeout Find ways to use this to your advantage.

    3) Despite the slowness and/or brokenness of (2), the site admins haven't fixed
    the misconfiguration. This means they are some combination of clueless and/or
    lazy, and this is a tolerated/accepted state of affairs. Find ways to use this
    to your advantage. ;)

    It's not so much a vulnerability in and of itself, as a warning signal that there
    are probably lots of OTHER issues with the network.

    Remember: Nothing screams "poor workmanship" quite like wrinkles in the duct tape. ;)

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: martin f krafft: "[Full-Disclosure] Re: a secure base system"

    Relevant Pages

    • Re: Help with initial small org AD setup convention when using DMZ network
      ... Consider using Dynamic DNS internally (aka Active Directory Integrated ... > firewall which then connects the public IP dmz network to a private IP ... > domain name for such subnets based on the nearest airport code, ... > servers to serve acme.com names for external users. ...
      (microsoft.public.win2000.active_directory)
    • Help with initial small org AD setup convention when using DMZ network
      ... firewall which then connects the public IP dmz network to a private IP ... domain name for such subnets based on the nearest airport code, ... Yahoo to manage my externally-visible DNS names on the acme.com domain. ... and servers that use this domain, ...
      (microsoft.public.win2000.active_directory)
    • Re: Change IP subnet for a site
      ... > The only problem being that the network is part of a private network in ... > clients are connected, but I have to allow for the possibility that they ... >>> servers. ... >>> DNS to ensure proper DNS registration. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Creating a new AD
      ... "Jorge Silva" wrote: ... I have pulled this setup from a different network and want to configure it ... I tried to change the ip setup on all these servers and restarted dns and ... i did a dnsflush and dns register and i am still not ...
      (microsoft.public.windows.server.active_directory)
    • Re: Creating a new AD
      ... MCSE, MVP Directory Services ... I have pulled this setup from a different network and want to configure it ... I tried to change the ip setup on all these servers and restarted dns and ... i did a dnsflush and dns register and i am still not ...
      (microsoft.public.windows.server.active_directory)