<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>thinking sysadmin &#187; nat</title>
	<atom:link href="http://andyleonard.com/tag/nat/feed/" rel="self" type="application/rss+xml" />
	<link>http://andyleonard.com</link>
	<description>qstat -u aleonard -s z</description>
	<lastBuildDate>Fri, 30 Jul 2010 17:47:40 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Thought you fixed that DNS spoofing bug?  You might need to think again.</title>
		<link>http://andyleonard.com/2008/07/27/thought-you-fixed-that-dns-spoofing-bug-you-might-need-to-think-again/</link>
		<comments>http://andyleonard.com/2008/07/27/thought-you-fixed-that-dns-spoofing-bug-you-might-need-to-think-again/#comments</comments>
		<pubDate>Sun, 27 Jul 2008 15:14:21 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[nat]]></category>
		<category><![CDATA[spoofing]]></category>

		<guid isPermaLink="false">http://andyleonard.com/?p=55</guid>
		<description><![CDATA[So you thought you fixed the DNS spoofing vulnerability that was all over the news this month?  You applied the patches and moved on to the other fifty-seven things crowded on your to-do list, thinking that you were safe?  If your resolvers are behind a NAT, you might want to think again, smart [...]]]></description>
			<content:encoded><![CDATA[<p>So you thought you fixed the <a href="http://www.doxpara.com/?p=1185">DNS spoofing vulnerability</a> that was all over the news this month?  You applied the patches and moved on to the other fifty-seven things crowded on your to-do list, thinking that you were safe?  If your resolvers are behind a NAT, you might want to <a href="http://blogs.iss.net/archive/dnsnat.html">think again</a>, smart guy.<br />
<span id="more-55"></span><br />
In a nutshell, your handy-dandy NAT box is quite possibly making your resolver&#8217;s now-random UDP source ports sequential, making you vulnerable again.  The only &#8220;vendors&#8221; I&#8217;m aware of that don&#8217;t have this issue are Linux&#8217;s IPTables and OpenBSD&#8217;s PF (also available on FreeBSD, of course) &#8211; funny that, since those guys aren&#8217;t really vendors at all.  I could be just ignorant or looking in the wrong place, but this doesn&#8217;t even seem to be on <a href="http://www.cisco.com/web/about/security/intelligence/dns-bcp.html">Cisco&#8217;s radar</a> right now, for example.</p>
<p>The tester in the sidebar at <a href="http://www.doxpara.com/">DoxPara Research</a> seems to do a good job of testing your configuration end-to-end for this vulnerability.</p>
<p>(File this under &#8220;Just another reason why NAT is evil.&#8221;)</p>
]]></content:encoded>
			<wfw:commentRss>http://andyleonard.com/2008/07/27/thought-you-fixed-that-dns-spoofing-bug-you-might-need-to-think-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
