<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; dns security</title>
	<atom:link href="http://www.darknet.org.uk/tag/dns-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Is Google Public DNS Safe?</title>
		<link>http://www.darknet.org.uk/2009/12/is-google-public-dns-safe/</link>
		<comments>http://www.darknet.org.uk/2009/12/is-google-public-dns-safe/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 09:58:17 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General News]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[dan-kaminsky]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[dns exploit]]></category>
		<category><![CDATA[dns security]]></category>
		<category><![CDATA[google dns]]></category>
		<category><![CDATA[google dns service]]></category>
		<category><![CDATA[google public dns]]></category>
		<category><![CDATA[hd-moore]]></category>
		<category><![CDATA[public dns]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2358</guid>
		<description><![CDATA[Google recently launched a public DNS service similar to the popular service over at OpenDNS, you can find it on Googlecode here &#8211; http://code.google.com/speed/public-dns/. The first obvious reaction for the infosec crowd (with all the recent DNS flaws), is to question the security of the Google DNS service. HD Moore has done some good analysis [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p><a href="http://www.darknet.org.uk/tag/google/">Google</a> recently launched a public DNS service similar to the popular service over at <a href="http://www.opendns.com/">OpenDNS</a>, you can find it on Googlecode here &#8211; <a href="http://code.google.com/speed/public-dns/">http://code.google.com/speed/public-dns/</a>.</p>
<p>The first obvious reaction for the infosec crowd (with all the recent <a href="http://www.darknet.org.uk/2008/07/exploit-for-kaminsky-dns-bug-goes-wild/">DNS flaws</a>), is to question the security of the Google DNS service.</p>
<p>HD Moore has done some good analysis on the service as outlined below.</p>
<blockquote><p>Yesterday, Google launched its new Public DNS service. Among the benefits that Google is claiming for the new service is that it helps to secure DNS for users. Is that an accurate claim?</p>
<p>One of the big issues that security researcher Dan Kaminsky disclosed about DNS insecurity in 2008 was that DNS request information isn&#8217;t quite as random as it should be. The way DNS works is that each DNS request is supposed to carry with it a random number transaction ID. But it turns out that the random number is only one out of 65,000. DNS is at risk when there isn&#8217;t enough randomization and a hacker can &#8216;guess&#8217; the number.</p>
<p>So is Google&#8217;s Public DNS random enough? I got a comment from famed security researcher, H D Moore on that point. Moore knows what he&#8217;s talking about when it comes to DNS exploits as his Metasploit tool was among the first to have a weaponized version of the Kaminsky DNS flaw.</p></blockquote>
<p>It seems like the port allocation of the Google DNS system is adequately random even though it&#8217;s drawing from a fairly small port range.</p>
<p>So the claims this could be a more secure DNS server for most systems are true, it will protect against DNS cache poisoning attacks at least.</p>
<blockquote><p>Moore has now put together a mapping of Google&#8217;s source port distribution on the Public DNS service. In his view, it looks like the source ports are sufficiently random, even though they are limited to a small range of ports.</p>
<p>According to HD, it looks like Google&#8217;s focus on security might be on the right track and the DNS could be good at preventing cache poisoning attacks.</p>
<p>His sample size is only 10,000 requests here, which isn&#8217;t a huge number but does give a decent sample in my view. He has also graphed source ports, transaction IDS and a comparison of source ports to those transaction IDs.</p></blockquote>
<p>I&#8217;ll switch over from OpenDNS and give the Google system a try, maybe it&#8217;ll reduce the lag time a little.</p>
<p>If anyone else is already using it, do share with us your thoughts in the comment section below.</p>
<p></p>
<p>Source: <a href="http://blog.internetnews.com/skerner/2009/12/is-google-public-dns-safe-look.html">Internet News</a> (<em>Thanks Navin</em>)</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Is+Google+Public+DNS+Safe%3F+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2358+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/12/is-google-public-dns-safe/&amp;t=Is+Google+Public+DNS+Safe%3F" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/12/is-google-public-dns-safe/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/12/is-google-public-dns-safe/&amp;title=Is+Google+Public+DNS+Safe%3F" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/12/is-google-public-dns-safe/&amp;title=Is+Google+Public+DNS+Safe%3F" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/12/is-google-public-dns-safe/&amp;title=Is+Google+Public+DNS+Safe%3F" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/12/is-google-public-dns-safe/&amp;title=Is+Google+Public+DNS+Safe%3F" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F12%2Fis-google-public-dns-safe%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/12/is-google-public-dns-safe/feed/</wfw:commentRss>
		<slash:comments>15</slash:comments>
		</item>
		<item>
		<title>PorkBind v1.3 &#8211; Nameserver (DNS) Security Scanner</title>
		<link>http://www.darknet.org.uk/2008/09/porkbind-v13-nameserver-dns-security-scanner/</link>
		<comments>http://www.darknet.org.uk/2008/09/porkbind-v13-nameserver-dns-security-scanner/#comments</comments>
		<pubDate>Mon, 15 Sep 2008 07:25:13 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[dns scanner]]></category>
		<category><![CDATA[dns security]]></category>
		<category><![CDATA[dns vulnerability]]></category>
		<category><![CDATA[hacking dns]]></category>
		<category><![CDATA[hacking-networks]]></category>
		<category><![CDATA[nameserver scanner]]></category>
		<category><![CDATA[namserver security]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[porkbind]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1012</guid>
		<description><![CDATA[This program retrieves version information for the nameservers of a domain and produces a report that describes possible vulnerabilities of each. Vulnerability information is configurable through a configuration file; the default is porkbind.conf. Each nameserver is tested for recursive queries and zone transfers. The code is parallelized with libpthread. Changes for v1.3 Wrote in-a-bind shell [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>This program retrieves version information for the nameservers of a domain and produces a report that describes possible vulnerabilities of each. </p>
<p>Vulnerability information is configurable through a configuration file; the default is porkbind.conf. Each nameserver is tested for recursive queries and zone transfers. The code is parallelized with libpthread.</p>
<p><strong>Changes for v1.3</strong></p>
<ul>
<li>Wrote in-a-bind shell script that scans random domain names from DMOZ</li>
<li>Implemented recursive query testing</li>
<li>Changed porkbind.conf to use CVE numbers in addition to CERT alerts</li>
<li>Modified text displayed on stdout to make it more parsable</li>
<li>Licensed with GNU Lesser General Public License</li>
<li>Fixed timeout/concurrency/memory corruption bugs</li>
<li>
Fixed improper comparison of alpha/beta version numbering bug</li>
<li>Added typecasts to silence compiler warnings</li>
</ul>
<p>The tool now scans for 14 flaws and reports CVE numbers &#038; CERT.</p>
<p>You can download PorkBind v1.3 here:</p>
<p><a href="http://www.innu.org/~super/tools/porkbind-1.3.tar.gz">porkbind-1.3.tar.gz</a></p>
<p></p>
<p>Or read more <a href="http://www.innu.org/~super/tools/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=PorkBind+v1.3+%E2%80%93+Nameserver+%28DNS%29+Security+Scanner+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1012+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/09/porkbind-v13-nameserver-dns-security-scanner/&amp;t=PorkBind+v1.3+%E2%80%93+Nameserver+%28DNS%29+Security+Scanner" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/09/porkbind-v13-nameserver-dns-security-scanner/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/09/porkbind-v13-nameserver-dns-security-scanner/&amp;title=PorkBind+v1.3+%E2%80%93+Nameserver+%28DNS%29+Security+Scanner" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/09/porkbind-v13-nameserver-dns-security-scanner/&amp;title=PorkBind+v1.3+%E2%80%93+Nameserver+%28DNS%29+Security+Scanner" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/09/porkbind-v13-nameserver-dns-security-scanner/&amp;title=PorkBind+v1.3+%E2%80%93+Nameserver+%28DNS%29+Security+Scanner" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/09/porkbind-v13-nameserver-dns-security-scanner/&amp;title=PorkBind+v1.3+%E2%80%93+Nameserver+%28DNS%29+Security+Scanner" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F09%2Fporkbind-v13-nameserver-dns-security-scanner%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/09/porkbind-v13-nameserver-dns-security-scanner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

