Login: Password: Forget password? / Register New User 
logo
Home Home | RSS feed - Onekit.com Software Magazine (Windows PC Software News) Current issue Current issue | RSS feed - Onekit.com Software Magazine (Latest Forum Topics) Forum and Community Forum & Community | Onekit's Software OneKit's Software | Live Chat with Support Team Support []
Games Graphics & Design MP3 & Audio Internet & Networks System & Utilities Home & Education Business WebDev SoftDev
The best test for vulnerability to the DNS flaw
Issue: July 2008 > Internet & Networks > Article "The best test for vulnerability to the DNS flaw"

The best test for vulnerability to the DNS flaw (The best test for vulnerability to the DNS flaw)  The best test for vulnerability to the DNS flaw

Internet & Networks
Advertisement on Onekit.com Software Magazine
Not only is there is a flaw in the Domain Name System, there is also a flaw in the suggested ways to test whether your computer is vulnerable.

Many articles suggest going to Web site x or y to run vulnerability tests. (I'm guilty of this too.) But the nature of the problem is that you can't trust Web site names.

The fallacy is simple: use a name you can't trust to see if you can trust a name.

As I explained in "What you need to know about the latest DNS flaw," every Web site can be accessed by an IP address. The DNS flaw does not affect this rare, but quite valid, method of addressing Web sites. Thus, it's the best approach for an online vulnerability test.

One often-cited vulnerability test is offered by the DNS Operations, Analysis, and Research Center (DNS-OARC) at: https://www.dns-oarc.net/oarc/services/dnsentropy

I asked them about using an IP address to get to their online test and was told (thanks, Duane) that the test is also available at:

http://149.20.3.33/test/



To me, this is the best vulnerability test for the current DNS flaw.

While this link bypasses the introduction to the topic offered by DNS-OARC, hopefully your computer is safe and you won't need to read about the problem. If all is well, it will report "great" for both the source port randomness and the transaction ID randomness.

If you are vulnerable, see "A cheatsheet for defending against the DNS flaw."
July 30, 2008 Author: Michael Horowitz


There is no user's comments | Post your comment

Related Links:
Advertisement Advertisement
about / contact us | Copyright 2003-2008 - Software Magazine, onekit.com, Legal Notices