Will Craddock's Adventures in Technology
"the ramblings of another geek"

Is Your DNS Patched?

July 27, 2008 11:27 by will.craddock

Rodney from Microsoft Canada forwarded me this, to get it pushed out to as many people as possible. 

In case you have been living under a rock for the past month you have most likely heard about the DNS cache exploit recently discovered by Dan Kaminsky.  This might be one of the most severe flaws discovered as it was cross platform affecting everything from Windows to Linux, UNIX, Cisco IOS etc....  It was so big in fact that all the major vendors worked together to get the patch issued on the same day.  The flaw would allow an attacker to insert a malicious DNS record into the cache.  As an end user you type in www.technet.com and rather than get the proper IP address the cache delivers the malicious IP address sending you to ????  You can find out more on the details of the flaw at Dan's blog.

You should also make sure that you are patched.  Make sure that your upstream ISP DNS servers are patched by calling them or using Dan's DNS Checker at the top of his website.

So why all of a sudden a rush to ensure you are patched?  Well the patches issued by the vendors have been reverse engineered and exploit code has been published!  Dan has said many times that this is an extremely easy to launch exploit that could be implemented in seconds.

MS08-037 - Vulnerabilities in DNS Could Allow Spoofing (953230)

KB953230 - Vulnerabilities in DNS could allow spoofing

Go. Read. Patch. Now.

And when you are done, copy and paste this blog post to your blog, email it to your IT Pro buddies, get the word out!

If you have links to the patches from other vendors, please leave a comment with the URL!


Be the first to rate this post

  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Related posts

Comments

December 12. 2008 08:43

Gravatar



hola,

Me encanta este puesto. Very Nice artículo para este puesto. Quiero compartir con otros. i poner este comentario como parte de agradecimiento para usted. gracias.

saludos cordiales,
Busby

Busby SEO Test

May 28. 2009 01:42

Gravatar

It should takes this blogengine so that they made a nice information soon,thanks for sharing it!

Pinoy Teen BigBrother

June 21. 2009 04:58

Gravatar

DNS cache poisoning is a maliciously created or unintended situation that provides data to a caching Domain Name System server that did not originate from authoritative Domain Name System (DNS) sources. This can happen through improper software design, misconfiguration of name servers, and maliciously designed scenarios exploiting the traditionally open-architecture of the DNS system.

Auto lease

September 22. 2009 02:11

Gravatar

I had the same concerns … but I’ve never seen a problem with any of our sites being penalized in any way

Gucci Hand bag

Gucci Hand bag

November 13. 2009 02:57

Gravatar

I just bought the 360 today and I'm trying to get it set up. In my network connections I am connected and bridged on both my wireless and local area connection. And my network bridge is also connected. However when I do the Xbox live test the DNS fails. I looked on my computer and found my DNS and manually put it in but it still is not working. What is the problem?

fourposter beds

November 20. 2009 02:54

Gravatar

I have noticed my router has an option to use dynamic DNS. What are the pros and cons of using this service?

pat test equipment

November 20. 2009 06:15

Gravatar

I have a web page that has my web cam on it and I have to keep changing the ip address in the HTML code. Can Dynamic DNS fix this problem and how can I do it?

spas with accommodation

November 23. 2009 00:30

Gravatar

I've not been able to access the web on my laptop because of DNS problems so I am wondering how I can fix my DNS settings? I am connected through a Speed Stream modem/router if that helps. Thanks in advance!

Teeth Whitener

November 23. 2009 05:03

Gravatar

Currently what I do is that when i want to go to an online banking site, I clear my browser cache and cookies. Then i restart the browser. Then I manually enter the url , carefully making sure I don't mistype.

SEO

November 23. 2009 21:43

Gravatar

I have a personal website on a free web host.I have also registered a domain name with another company.How do I put the DNS settings right, in both the host and the registrar's websites, to point the domain name to my website?There are many settings and I don't understand what's going on.
Thanks for your help!

pat testers

November 23. 2009 21:56

Gravatar

i just scan a w2k3 DC server with nap tool, and discovered a lot of open ports.can someone tell me a way to secure or patch up these open ports please?

pat testers

November 24. 2009 02:48

Gravatar

How do I get my DNS servers in their proper search order?
The network connections scan of my computer always states my DNS servers not in order and therefore my LAN fails the scan test.

Digital Cameras

November 24. 2009 22:15

Gravatar

I know that there is a security breach in DNS but is it solved or not and is their a web site to know more details?

poolscaping

November 25. 2009 03:14

Gravatar

I have MAC right now, and I have never had a problem with viruses or anything the whole time I have used it.It might be smart to install a security system anyways, there is always a chance of a virus, but like I said, I have never had a problem with mine and I have never installed one before.

Corporate Events in Harbour Cruises

November 25. 2009 23:30

Gravatar

I need to install windows server 2003 on a computer that currently has windows XP installed on it. When I go to install windows server, an error message comes up saying that I can not upgrade from xp to server 2003. When I try to do a clean install, a blue screen error message comes up saying that a problem has occurred, the computer was shut down to prevent damage to your computer. Any Ideas?

computer data recovery

November 26. 2009 23:41

Gravatar

The i pod manual says that I should have an i pod contacts tab underneath my i pod, but I don't. I have the 4th generation Nano,So it should be there! Help I stink at technology! I also don't have Microsoft outlook or outlook express. Can I just put the contacts on myself?

business mobile phones

November 30. 2009 00:00

Gravatar

Will anyone continue to support Microsoft or help in the development with the use of Linux? Why?

boat builders

December 3. 2009 00:58

Gravatar

Can anyone provide a list or links of Microsoft's all new invented technology and product like
Windows Azure
Microsoft Health vault
Microsoft Hohm
A little wiki on microsoft inventions.

industrial cleaning

December 3. 2009 05:39

Gravatar

Just try to smile for about 2-3 mins then you can get back to work

fast payday loans

December 11. 2009 00:00

Gravatar

I have a hosting account at windows server.i try to send mail with php code but it is not working .all help are accepted .

casino on net

December 14. 2009 01:17

Gravatar

Open DNS is really a great website to prevent internet abuse. But the problem is what if someone else using my computer changed the DNS setting? In other words, removed the numbers of the site and used another. In this case Open DNS will not work and consequently, all previously blocked domains will open and work. So, my question is how to prevent others from doing that?

air conditioning

December 14. 2009 02:19

Gravatar

My MBP running the latest lepord patch, has been having many troubles with keeping an internet connection. Whenever i am connected to my home or schools connection thanks a lot for the post.

Christmas hampers

December 16. 2009 23:34

Gravatar

Open DNS is a very useful site used for preventing internet use. I am also a great fan Dan's DNS Checker .

Personal training Gold Coast

December 18. 2009 15:58

Gravatar

<P>this truly aids, now i receive the troubles and i donot know how to work out,
i search yahoo and discovered your blog,
thanks once again</P><P>one thing, may i post this entry on my site? i will add the source and credit to your site.</P><P>regards!</P>

logan sam

December 21. 2009 02:14

Gravatar

I've been unable to get into my hot mail account or any other website that requires security.I'm able to get to the front page of hot mail, but when I want to log on it takes me to a page that says "cannot be displayed" and at the bottom it says something about a DNS error. I have wireless internet, and my security levels are low..how can I possibly fix this? Or do you need more details?

laser whitening brisbane

December 22. 2009 03:04

Gravatar

My router doesn't work and i think it is something to do with the ip address and dns server i am using.i have tried running cmd but it doesn't work. Help!

facelift

December 23. 2009 05:11

Gravatar

Want to get online Business marketing services.like marketing services like lead generation, market research and analysis, search engine optimization, product launch, product promotion- through print and digital medium, development of website, internet marketing services, e-commerce solution. Can any body give helpful suggestions to me.

Canon EOS

December 28. 2009 03:58

Gravatar

my computer is newly reformat. And the guy who reformat my computer installed an old version of Microsoft word 2000. And it SUCKS! I need links on downloading a higher version of Microsoft word. Please help me. Please indicate the link:) Thank you so much!

all weather garden furniture

December 30. 2009 00:25

Gravatar

Pretty good post. I just stumbled upon your blog and wanted to say that I have really enjoyed reading your blog posts. Any way I'll be subscribing to your feed and I hope you post again soon.

personal loans

December 30. 2009 22:00

Gravatar

I don't really understand what that means to honest, and I don't know what to do. I've been having a few problems along with that. I can't log in to some places because it thinks spoofing too. So if anyone could help me that would be really great

free online roulette

December 31. 2009 01:58

Gravatar

I have com-cast cable and use modem only. When I go to Network property, I see manually assigned DNS server IP address. What is the purpose of DNS server?

facelift

January 11. 2010 05:22

Gravatar

I have a Belkin router and it was working find and then a DNS problem came up. I typed in 192.168.2.1 in and the problem screen came up but I do not know how to fix the problem. I have charter and I do not know their DNS.

boatbuilding

January 14. 2010 02:26

Gravatar

Do not save your loving speeches For your friends till they are dead; Do not write them on their tombstones, Speak them rather now instead.

pay day loans

January 19. 2010 04:58

Gravatar

This can happen through improper software design, misconfiguration of name servers, and maliciously designed scenarios exploiting the traditionally open-architecture of the DNS system.

wedding dress

January 24. 2010 09:52

Gravatar

This is an interesting topic. Thanks for comming up with it, now I understand a little more about it.

Buenos Aires real estate guide

January 29. 2010 06:23

Gravatar

The author is 100% correct and sure what he had mentioned

cheapest personal loans

February 1. 2010 09:30

Gravatar

Is Your DNS Patched?. I need to read more on this topic..Thanks for sharing a nice info....

Hair Coloring

February 11. 2010 08:15

Gravatar

Deep within man dwell those slumbering powers; powers that would astonish him, that he never dreamed of possessing; forces that would revolutionize his life if aroused and put into action.

payday loans

February 12. 2010 00:55

Gravatar

Is Your DNS Patched?. Well worth the read. thank you very much for taking the time to share with those who are starting on the subject. Greetings.

haircuts

February 12. 2010 10:21

Gravatar

It is better to err on the side of daring than the side of caution.

payday loans

February 12. 2010 19:10

Gravatar

Is Your DNS Patched?. Nice ... maybe you could update this. Thanks.

cook tips

February 12. 2010 20:19

Gravatar

Is Your DNS Patched?. This is just the information I am finding everywhere. Thanks for your blog, I just subscribe your blog. This is a nice blog..

test

February 12. 2010 20:47

Gravatar

I admire what you have done here. I like the part where you say you are doing this to give back but I would assume by all the comments that this is working for you as well.

teeth whitening kits

February 13. 2010 01:08

Gravatar

Is Your DNS Patched?. Nice ... maybe you could update this. Thanks.

cooking master

February 15. 2010 07:59

Gravatar

This is my first time i visit here. I found so many interesting stuff in your blog especially its discussion. From the tons of comments on your articles, I guess I am not the only one having all the enjoyment here! keep up the good work.

Colon cleansers

February 18. 2010 06:06

Gravatar

have already bookmarked your this page...Now I don’t have enough time for read but by reading beginning part I must say...it was a positive start .. Would love to read further too...Thanks for great post

ucvhost

February 18. 2010 16:23

Gravatar

Choose a job you love, and you will never have to work a day in your life.

natural detox

February 20. 2010 18:57

Gravatar

I really enjoyed read your article, very interesting ...

ehliyet

February 21. 2010 11:34

Gravatar

Keep working ,great job!

Acne scar treatment

February 23. 2010 08:52

Gravatar

nice template and great article.thanks this is great information.

bağkur

February 23. 2010 16:48

Gravatar

Excellent post.I want to thank you for this informative read, I really appreciate sharing this great post. Keep up your work.

zerrin egeliler

February 24. 2010 14:44

Gravatar

In searching for sites related to web hosting and specifically comparison hosting linux plan web, your site came up.

mountain bike review

February 25. 2010 18:56

Gravatar

Wow this is an interesting article. I hope to see more in the future. While you're reading this you might as well check out http://www.lovelyanime.com for over 550 Anime series to watch online for FREE!

Watch Anime Online

March 1. 2010 18:11

Gravatar

Is Your DNS Patched?. I don�t know If I said it already but this so good stuff keep up the good work..

cats

March 1. 2010 18:59

Gravatar

Is Your DNS Patched?. Thank you for your help!.

cats

March 1. 2010 22:19

Gravatar

Is Your DNS Patched?. Thanks for great information I appreciate your work keep it up. thanks. .

flea

March 3. 2010 02:22

Gravatar

Pretty good post. I just stumbled upon your blog and wanted to say that I have really enjoyed reading your blog posts. Any way I'll be subscribing to your feed and I hope you post again soon.

San Francisco dermatologist

March 3. 2010 02:23

Gravatar

You got a really useful blog I have been here reading for about an hour. I am a newbie and your success is very much an inspiration for me.

Ephedra

March 3. 2010 02:24

Gravatar

Took me time to read all the comments, but I really enjoyed the article. It proved to be Very helpful to me and I am sure to all the commenters here! It's always nice when you can not only be informed, but also entertained! I'm sure you had fun writing this article.

Maternity Nightwear

March 3. 2010 03:03

Gravatar

Thanks for such a great post and the review, I am totally impressed! Keep stuff like this coming.

best weight loss pills

March 3. 2010 05:04

Gravatar

exclusive alcohol treatment Malibu

exclusive alcohol treatment Malibu

March 3. 2010 06:49

Gravatar

Tricastmedia focuses on developing simple to use mobile e-mail software and powerful user interface technologies for mobile devices.

Mobile User Interface Technology

March 5. 2010 18:38

Gravatar

Fine information, many thanks to the author. It is puzzling to me now, but in general, the usefulness and significance is overwhelming. Very much thanks again and good luck!

gazeteler

March 6. 2010 03:05

Gravatar

This can happen through improper software design, misconfiguration of name servers, and maliciously designed scenarios exploiting the traditionally open-architecture of the DNS system.

find cell number phone information

March 6. 2010 03:05

Gravatar

I try to do a clean install, a blue screen error message comes up saying that a problem has occurred, the computer was shut down to prevent damage to your computer. Any Ideas?

blog commenting service

March 7. 2010 03:32

Gravatar

Is Your DNS Patched?. my God, i thought you were going to chip in with some decisive insght at the end there, not leave it with �we leave it to you to decide�..

phone cell

March 7. 2010 06:08

Gravatar

Is Your DNS Patched?. Well, I just found your blog unexpectedly from the search engine. First time I saw it, I know it's a very informative blog. I got so many something new from here. Good work and thanks for that!.

duvet covers

March 7. 2010 09:03

Gravatar

Is Your DNS Patched?. Thanks for such a nice article.It includes very informative information about the article..

blood pressure

March 8. 2010 20:14

Gravatar

Is Your DNS Patched?. You are a very smart person!.

home industries

March 8. 2010 20:59

Gravatar

Is Your DNS Patched?. This is actually really interesting regarding your fact article here, This article is very informative..

weight loss

Add comment


(Will show your Gravatar icon)  

  Country flag




Live preview

March 10. 2010 16:02

Gravatar