JRDN
Jason Roysdon dot Net

Securing the internet with DNSSEC, one DNS query at a time

April 27th 2009 in Networking, Security

Dan Kaminski found one design flaw with the majority of DNS servers as well as exactly how to exploit it in a repeatable fashion. There are many other problems with DNS attacks that would be solved with DNSSEC.

Just what is DNS? DNS is how your computer learns the numeric IP address to connect to from a name, such as roysdon.net resolving as 208.202.125.53. DNSSEC is a Security feature adding on to DNS. DNSSEC allows servers to make cryptographic signatures on data they send, preventing forging or editing of information in the reply as a DNS query makes its way to the half dozen DNS servers it must go to.

Why is this a big deal? Say you work at acme.com, so you've told Internet Explorer to trust any acme.com domains. What if I send you an email or have a well-crafted webpage I get you to which has some bad mojo code (say some active-x installer or whatever) and I've poised your dns servers into thinking badserver.acme.com is pointed at the server hosting this code. Since you've already trusted acme.com, you'll not be warned and things will just install, etc. This is an over-simplification, but you get the point, and it is a real life problem.

The solution is to have DNSSEC signatures passed from servers and verifiable by your closest DNS server at your ISP or office.

More technical details in a future post.


One comment to...
“Securing the internet with DNSSEC, one DNS query at a time”
DNSSEC technical details « ROYSDON

[...] originally posted a more simplistic overview of DNSSEC that is a good first read if you’re new to the [...]




required



required - won't be displayed


Your Comment:

One cool feature of many TV capture cards is the ability to hook up an FM antenna and listen to the radio... We like a number of children's radio dramas, such as Adventures in Odyssey and Paws and Tales... Now they're available on our home DVR and accessible to any other networked device at our home. For on the go use, all we have to do is connect our Sansa music players (running Rockbox for Ogg and much more support) or cell phones to a PC, and drag and drop the files over.

Previous Entry

As of about a week ago, Verizon finally released an official Storm upgrade for the Blackberry OS (v4.7.0.148)....
Do this when you've got 2-3 hours to let it download, upgrade, and then fuss with your apps after (getting passwords stored again, mail server settings, etc.). I had to delete 4-5 apps from my phone before it would let me install it to clear up space. I think I deleted most of the Google/Youtube/Facebook type apps and that worked fine. Just reinstall them after the upgrade - plus then you'll have the latest versions.

Next Entry