Microsoft Windows Vista Community Forums - Vistaheads
FREE Anti Rootkit Software for Vista Users




Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.


Fasten your seatbelts, it's going to be a bumpy ride!

microsoft.public.windows.vista.security



Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Reply
  #1 (permalink)  
Old 4 Weeks Ago
Kayman
 

Posts: n/a
Fasten your seatbelts, it's going to be a bumpy ride!
DNS flaw discoverer says more permanent fixes will be needed
Current patch options merely stopgaps; worst attacks likely on the way
http://www.computerworld.com/action/...4&pageNumber=1

Eagerly awaiting ZA's reaction
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 4 Weeks Ago
Alun Jones
 

Posts: n/a
Re: Fasten your seatbelts, it's going to be a bumpy ride!
"Kayman" <kaymanDeleteThis@operamail.com> wrote in message
news:#slCVKg6IHA.3816@TK2MSFTNGP03.phx.gbl...
> DNS flaw discoverer says more permanent fixes will be needed
> Current patch options merely stopgaps; worst attacks likely on the way
> http://www.computerworld.com/action/...4&pageNumber=1
>
> Eagerly awaiting ZA's reaction


Well, good, because I'd hate to think the current state of patches are the
best we can do.

On Windows, we have an over-full netstat display, because DNS reserves 2500
ports; some services that haven't set the ReservedPorts registry key find
that their ports are sometimes (randomly) blocked by DNS reserving those
ports first.

On Linux, or other platforms using BIND, we have UDP-based daemons receiving
DNS responses on a random basis, because the DNS server accidentally picks
their port to send from.

"needs a little work" is a good description.

Alun.
~~~~
--
Texas Imperial Software | Web: http://www.wftpd.com/
23921 57th Ave SE | Blog: http://msmvps.com/alunj/
Woodinville WA 98072-8661 | WFTPD, WFTPD Pro are Windows FTP servers.
Fax/Voice +1(425)807-1787 | Try our NEW client software, WFTPD Explorer.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 4 Weeks Ago
Kayman
 

Posts: n/a
Re: Fasten your seatbelts, it's going to be a bumpy ride!
On Sat, 19 Jul 2008 23:37:07 -0700, Alun Jones wrote:

> "Kayman" <kaymanDeleteThis@operamail.com> wrote in message
> news:#slCVKg6IHA.3816@TK2MSFTNGP03.phx.gbl...
>> DNS flaw discoverer says more permanent fixes will be needed
>> Current patch options merely stopgaps; worst attacks likely on the way
>> http://www.computerworld.com/action/...4&pageNumber=1
>>
>> Eagerly awaiting ZA's reaction

>
> Well, good, because I'd hate to think the current state of patches are the
> best we can do.
>
> On Windows, we have an over-full netstat display, because DNS reserves 2500
> ports; some services that haven't set the ReservedPorts registry key find
> that their ports are sometimes (randomly) blocked by DNS reserving those
> ports first.
>
> On Linux, or other platforms using BIND, we have UDP-based daemons receiving
> DNS responses on a random basis, because the DNS server accidentally picks
> their port to send from.
>
> "needs a little work" is a good description.
>


Just a quick note...
http://www.doxpara.com/

Stay tuned
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 4 Weeks Ago
Anteaus
 

Posts: n/a
Re: Fasten your seatbelts, it's going to be a bumpy ride!
By the sound of things it's probably better NOT to apply these patches to
internal, non-internet-facing DNS servers, as if I read correctly they could
randomly interfere with other unrelated functions of the server.

Would you agree?

"Alun Jones" wrote:

> On Windows, we have an over-full netstat display, because DNS reserves 2500
> ports; some services that haven't set the ReservedPorts registry key find
> that their ports are sometimes (randomly) blocked by DNS reserving those
> ports first.
>
> On Linux, or other platforms using BIND, we have UDP-based daemons
> receiving DNS responses on a random basis, because the DNS server
> accidentally picks their port to send from.
>
> "needs a little work" is a good description.
>


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 4 Weeks Ago
Alun Jones
 

Posts: n/a
Re: Fasten your seatbelts, it's going to be a bumpy ride!
"Anteaus" <Anteaus@discussions.microsoft.com> wrote in message
news:03F8E5CE-CA89-490D-9814-A8730407BF4E@microsoft.com...
> By the sound of things it's probably better NOT to apply these patches to
> internal, non-internet-facing DNS servers, as if I read correctly they
> could
> randomly interfere with other unrelated functions of the server.


I wouldn't say "yes" or "no" to any patch this soon after it's released,
without knowing your environment and the systems that will be patched.

As with all significant behaviour changes, you should test it in your
environment, and follow appropriate workarounds.

It's a good idea, in general, to indicate to the operating system that
certain applications have reserved ports using the ReservedPorts registry
key - whether you apply or don't apply this patch. That way other
applications besides DNS won't try to poach a port that's already in use -
as is shown by the example of BIND DNS servers, an application can quite
easily cause traffic to be directed to a service, if it isn't kept away from
reusing that socket, and ReservedPorts is the Windows way to do that across
multiple applications.

Test the patch in your environment, if you have multiple DNS servers, make
sure it doesn't adversely affect your operations, and then deploy the patch.

Expect another patch to DNS - but it might not be this month, or for a
couple of months. Don't hold off patching because "there might be another
patch", use this as an opportunity to solidify your DNS testing methodology,
so that you can test more quickly with the next patch, whenever that might
occur.

DNS is starting to really show its age.

Alun.
~~~~

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
RIAA College Litigations Getting A Bumpy Ride Steve General Technology News 0 11-14-2007 18:10
Bumpy-Jumpy 1.0 Gamer Games Feed 0 06-12-2007 05:08
Microsoft test of "Halo 3" gets off to bumpy start Steve General Technology News 0 05-17-2007 11:38
Microsoft test of "Halo 3" gets off to bumpy start Steve General Technology News 0 05-17-2007 04:07
At the end of the ride Gene Fitzpatrick microsoft.public.windows.vista.general 6 03-02-2007 20:05


All times are GMT +1. The time now is 12:41.




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119