On CBS MoneyWatch: Report: Tiger to Pay Wife $60 Million
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 7 of 26:
Next »
« Previous
Re: Are private DNS servers exploitable?
Your scenario is not exploitable with the current code, because it is not possible to directly feed requests to your internal DNS server. Your setup is actually similar to most corporate setups, just on a smaller and less complex scale.

Extensions of the current code could be made where requests weren't made directly via the metasploit framework, but where your browser/email-client/etc is forced to make a large number of requests on your behalf. This could be done by getting you to click a malicious link or by you visiting a legit but hijacked website (either XSS bug or full control).

Depending on how your NAT router is setup will depend if you are vulnerable in that case or not.

Corporations have to worry about this because there are still many, many ways to kick-off DNS requests from the inside, through email servers, database servers, web functionality, etc etc.
Posted by: natron_   Posted on: 07/24/08 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

TTL  jahday | 07/24/08
He explained...  nmcfeters | 07/24/08
Close...  annominous | 07/24/08
Thanks for the clarification (NT)  nmcfeters | 07/24/08
Are private DNS servers exploitable?  NonZealot | 07/24/08
Not sure  nmcfeters | 07/24/08
Re: Are private DNS servers exploitable?  natron_ | 07/24/08
Re: Are private DNS servers exploitable?  natron_ | 07/24/08
Indeed.  jahday | 07/24/08
I'm 99% sure my router doesn't do DNS  NonZealot | 07/24/08
Unless  nmcfeters | 07/24/08
Yes  nmcfeters | 07/24/08
Yes and no  annominous | 07/24/08
Thanks for the answers, all of you  NonZealot | 07/24/08
Well... you might be a bigger target then you think  nmcfeters | 07/24/08
Yes, certainly vulnerable to that  NonZealot | 07/24/08
SuSE 10.2 works- DON'T UPGRADE  r_widell | 07/24/08
Has someone else confirmed this?  nmcfeters | 07/25/08
RE: Kaminsky suggests long-term fix will still have to be determined  annominous | 07/24/08
Indeed (NT)  nmcfeters | 07/24/08
Right.  jahday | 07/24/08
Actually  nmcfeters | 07/24/08
RE: TTL  natron_ | 07/24/08
Yes, this is correct  nmcfeters | 07/24/08
It would be better to handshake using UDP...  mrlinux | 07/25/08
RE: Kaminsky suggests long-term fix will still have to be determined, but patch now, or pay soon  phatkat | 07/25/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement
  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More