Skip to content

Thought you fixed that DNS spoofing bug? You might need to think again.

So you thought you fixed the DNS spoofing vulnerability that was all over the news this month? You applied the patches and moved on to the other fifty-seven things crowded on your to-do list, thinking that you were safe? If your resolvers are behind a NAT, you might want to think again, smart guy.

In a nutshell, your handy-dandy NAT box is quite possibly making your resolver’s now-random UDP source ports sequential, making you vulnerable again. The only “vendors” I’m aware of that don’t have this issue are Linux’s IPTables and OpenBSD’s PF (also available on FreeBSD, of course) - funny that, since those guys aren’t really vendors at all. I could be just ignorant or looking in the wrong place, but this doesn’t even seem to be on Cisco’s radar right now, for example.

The tester in the sidebar at DoxPara Research seems to do a good job of testing your configuration end-to-end for this vulnerability.

(File this under “Just another reason why NAT is evil.”)

Post a Comment

Your email is never published nor shared. Required fields are marked *
*
*