DNS Randomness Test

DNS Randomness Test

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
DNS Randomness Test Kayman 07-28-2008
Posted by Kayman on July 28, 2008, 9:39 am
If you were  Registered and logged in, you could reply and use other advanced thread options
"The test takes a few seconds to complete. When its done you'll see a page
where the transaction ID and source port randomness will be rated either
GREAT, GOOD, or POOR. If you see a POOR rating, we recommend that contact
your ISP and ask if they have plans to upgrade their nameserver software
before August 7th."
https://www.dns-oarc.net/oarc/services/dnsentropy

Posted by Twayne on July 28, 2008, 12:18 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> "The test takes a few seconds to complete. When its done you'll see a
> page where the transaction ID and source port randomness will be
> rated either GREAT, GOOD, or POOR. If you see a POOR rating, we
> recommend that contact your ISP and ask if they have plans to upgrade
> their nameserver software before August 7th."

Umm, I'd beware any stranger offering advice in case that appeals to
you. It's outright spam to begin with and of no known value or
recognition otherwise. It's designed to make you curious and want to
visit that URL where who knows what might go on? It'd be funny if it
weren't so stupid!




Posted by Geoff on July 28, 2008, 1:11 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
wrote:

>> "The test takes a few seconds to complete. When its done you'll see a
>> page where the transaction ID and source port randomness will be
>> rated either GREAT, GOOD, or POOR. If you see a POOR rating, we
>> recommend that contact your ISP and ask if they have plans to upgrade
>> their nameserver software before August 7th."
>
>Umm, I'd beware any stranger offering advice in case that appeals to
>you. It's outright spam to begin with and of no known value or
>recognition otherwise. It's designed to make you curious and want to
>visit that URL where who knows what might go on? It'd be funny if it
>weren't so stupid!
>
>
As an advisory it lacks any real information. This is supposed to be an
advisory about the Kaminsky DNS vulnerability but is of limited use to end
users other than to generate grass roots movement from users to get ISP's
to upgrade their DNS code.

The full text of the dns-oarc.net page follows:

----------------------

US-CERT's Vulnerability Note VU#800113 describes deficiencies in the DNS
protocol and implementations that can facilitate cache poisoning attacks.
The answers from a poisoned nameserver cannot be trusted. You may be
redirected to malicious web sites that will try to steal your identity or
infect your computers with malware. On August 7, 2008, Dan Kaminsky will
release the details of how such attacks can be launched against vulnerable
DNS resolvers.

The essence of the problem is that DNS resolvers don't always use enough
randomness in their transaction IDs and query source ports. Increasing the
amount of randomness increases the difficulty of a successful poisoning
attack.

This page exists to help you learn if your ISP's nameservers are vulnerable
to this type of attack. If you click on the button below, we will test the
randomness of your ISP DNS resolver.


The test takes a few seconds to complete. When its done you'll see a page
where the transaction ID and source port randomness will be rated either
GREAT, GOOD, or POOR. If you see a POOR rating, we recommend that contact
your ISP and ask if they have plans to upgrade their nameserver software
before August 7th.

See porttest for another way to check your resolver from a Unix
commandline.

----------------------

See also: http://www.kb.cert.org/vuls/id/800113

Posted by David H. Lipman on July 28, 2008, 4:30 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>> "The test takes a few seconds to complete. When its done you'll see a
>> page where the transaction ID and source port randomness will be
>> rated either GREAT, GOOD, or POOR. If you see a POOR rating, we
>> recommend that contact your ISP and ask if they have plans to upgrade
>> their nameserver software before August 7th."

| Umm, I'd beware any stranger offering advice in case that appeals to
| you. It's outright spam to begin with and of no known value or
| recognition otherwise. It's designed to make you curious and want to
| visit that URL where who knows what might go on? It'd be funny if it
| weren't so stupid!



No. Both Kayman and the site are legitimate and most importantly this is a good
test
concerning the US CERT
Vulnerability Note VU#800113

Reference:
http://www.kb.cert.org/vuls/id/800113

This is NOT spam!

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by Lon on July 28, 2008, 9:14 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Twayne wrote:
>> "The test takes a few seconds to complete. When its done you'll see a
>> page where the transaction ID and source port randomness will be
>> rated either GREAT, GOOD, or POOR. If you see a POOR rating, we
>> recommend that contact your ISP and ask if they have plans to upgrade
>> their nameserver software before August 7th."
https://www.dns-oarc.net/oarc/services/dnsentropy
>
> Umm, I'd beware any stranger offering advice in case that appeals to
> you. It's outright spam to begin with and of no known value or
> recognition otherwise. It's designed to make you curious and want to
> visit that URL where who knows what might go on? It'd be funny if it
> weren't so stupid!
>
>
>
I'd also beware of self appointed security experts who do not recognize
the site www.dns-oarc.net.

Similar ThreadsPosted
only test- solo test March 5, 2006, 6:41 am
Re: test only August 26, 2006, 9:56 am
ONLY A TEST! November 18, 2007, 10:55 am
Re: Trial/Test March 19, 2006, 10:01 pm
A new 'Beta' test from Panda July 26, 2007, 5:03 pm
Anti-Malware Test April 15, 2008, 8:22 pm
tools to test server Security September 24, 2005, 10:27 pm
Test to see if my posts show up in my reader. October 16, 2008, 3:26 pm
Re: Do you ever test VISTA i have found lots of problems ?! March 24, 2006, 10:45 am
RE: Do you ever test VISTA i have found lots of problems ?! March 24, 2006, 11:40 am

The site map in XML format XML site map

Contact Us | Privacy Policy