Feb 3

     Security attacks arise in many forms. Attacking a name server is one of them. If you are a name-server operator, the test on vulnerable recursive service from http://recursive.iana.org/ would be a good guide for further investigation on your system.

     The discovery of a highly-effective cache poisoning attack that can affect name servers providing recursive name service has made it important that such servers be patched to mitigate against the problem. Furthermore, the risk of cache poisoning for servers that share recursive and authoritative functions can cross-pollinate the authoritative function with incorrect data. This tool is designed to assess the authorities for a given domain and determine whether they provide vulnerable recursive service.

Well, let’s perform a test on my domain name!

Oh, not bad, right ;)

 

If you were me, which server would you think of next?
- SIIT, Thamasart University (the name server of my institute)

you can also test on tu.ac.th - that will give a similar result.

 

Let’s see neighbor institutes:
- Chulalongkorn University

- Mahidol University

     Now, your turn! check if your server is reliable on its security. If you are a name server operator and you have found such a loophole, it’s high time for you to fix/report the problem.


d0m3z

Feb 2

NO ONE KNOWS, BUT I DO

NO ONE SEES, BUT I DO

LOVE IS BEAUTIFUL

LUST IS DREADFUL

WHEN THE OPPOSITION IS COMPROMISED

SOMETHING GOES WRONG

SOMETHING CHANGES

I AM GUILTY

d0m3z