Morgan Storey's Security Blog.

Wednesday, 27 August 2008

Pretty lights 

More on DNS I know. May as well be another person beating a dead horse. But I give you pretty: http://www.doxpara.com/?p=1206
It is a video of the patched and not patched world wide. It intrigues me that there is a blinking light on the map of Australia about 3 hours north of Adelaide, I doubt it is Alice Springs, to south, maybe Coober Peadie if my geography serves.
Onto some more supposition by me (mainly in reply to Dan [the guy who discovered the Researched the DNS flaw] here);
I agree with what has been said, that we need more security on an inherintly in-secure network. But some (percieved) anonymity and some plain text is good, and what the internet is all about.
Could you imagine every site moving to https, for starters what is the point, who needs to read my blog through an encrypted channel? Really why, I don't really have any direct post functionality, and only a handful of readers, it is not like I am directing them to blindly do anything either.
Onto DNS, I was thinking the other day of another way to fix the issue. Deploy a port knocking technique on the reply based on the query, so that ports would have to be knocked in the correct order on the DNS server pre accepting back the lookup. Similar to the way a person gets into a safe, knowing the numbers isn't good enough you need to know the sequence. This would stop NAT being an issue as the DNS server can make the request out on all ports getting an auto map back on these ports. And would be more secure as the attacker would have to guess the right ports to knock on the way back, or read the request and then generate the reply and reply back, but if they can do that they are already in the middle and its game is over.
What do you think?
Peace out all, especially Dan, good job.

Labels: ,


Comments: Post a Comment

Archives

July 2008   August 2008   September 2008   October 2008   November 2008   January 2009   June 2009   September 2009   November 2009   December 2009   February 2010   April 2010   July 2010   September 2010   February 2011   January 2012  

This page is powered by Blogger. Isn't yours?

 

 

Home
  Mobile Blog
  Security Blog
About me
Fiona
My Friends
My Computers
About LRP
My Family
My Jaunts
My Projects
My Resume
Other Journals
Downloads
Links

E-mail Me

No Clean Feed - Stop Internet Censorship in Australia

RSS Feed        Atom Feed
RSS or ATOM

 

Fight Spam!

eXTReMe Tracker