Networking
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
User Name:
Password:
Remember me
Go Back   Web Development Archives Mailing Lists Networking

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Display Modes
 
Unread Web Development Archives Sponsor:
  #1  
Old July 31st, 2008, 09:40 PM
Alan Clegg
Guest
Dev Archives Newbie (0 - 499 posts)
 
Posts: n/a  
Time spent in forums:
Reputation Power:
Risks of patched servers behind de-randomizing NAT

David Carmean wrote:
I seem to have lost a message where somebody from ISC (Paul?) was going to
release an updated/new advisory regarding the source-port de-randomizing
effects of many NAT implementations will have upon patched servers.
I don't know what Paul (or whoever) was going to say, but I'll say the
following:

If I can get your nameserver to resolve a specific query (consider, as
Evan said earlier, an e-mail with a link in it that someone in your
organization might click on), and that query is from a device that shows
up on the Internet as a resolver with non-random source ports, I may
very well be able to poison your cache.

Consider that there are other ways to force "internal" servers to do
predictable outbound queries (think about the SMTP protocol for a moment)

Randomize the port numbers.

Please.

AlanC

Reply With Quote
  #2  
Old July 31st, 2008, 09:40 PM
David Carmean
Guest
Dev Archives Newbie (0 - 499 posts)
 
Posts: n/a  
Time spent in forums:
Reputation Power:
Risks of patched servers behind de-randomizing NAT

I seem to have lost a message where somebody from ISC (Paul?) was going to
release an updated/new advisory regarding the source-port de-randomizing
effects of many NAT implementations will have upon patched servers.

Many of the folks I'm working with are unconcerned about this problem,
because they cannot come up with an attack scenario against a recursive
server behind a [NATting] firewall. They are also apparently hearing
claims from our firewall vendor (starts with a letter between I and K) that
this is not a big deal for servers behind a [their?] firewall. (Were they
not invited to The Big Meeting?)

Can we get a reading from Those Who Know about how likely it is that
BadGuys can trick a client inside such a firewall to facilitate an attack
against an internal recursive server (said server can query through the firewall).

Thanks.

Reply With Quote
Reply

Viewing: Web Development Archives Mailing Lists Networking > Risks of patched servers behind de-randomizing NAT


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2009 by Developer Shed. All rights reserved. DS Cluster 6 Hosted by Hostway
Stay green...Green IT