<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-2914337944584630860.post3863294902058662222..comments</id><updated>2008-11-10T11:23:47.827-08:00</updated><title type='text'>Comments on Jon Hart's Blog: Mitigating DNS cache poisoning with PF</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.spoofed.org/feeds/3863294902058662222/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default'/><link rel='alternate' type='text/html' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html'/><author><name>Jon Hart</name><uri>http://www.blogger.com/profile/02857880233692933624</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>11</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2914337944584630860.post-4622367169433438323</id><published>2008-11-05T22:06:00.000-08:00</published><updated>2008-11-05T22:06:00.000-08:00</updated><title type='text'>Tommy,Since you didn't leave an email, I have to d...</title><content type='html'>Tommy,&lt;BR/&gt;&lt;BR/&gt;Since you didn't leave an email, I have to do this publicly.  No, I can't help you here.  Email me and thats a different story.&lt;BR/&gt;&lt;BR/&gt;-jon</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/4622367169433438323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/4622367169433438323'/><link rel='alternate' type='text/html' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html?showComment=1225951560000#c4622367169433438323' title=''/><author><name>Jon Hart</name><uri>http://www.blogger.com/profile/03410754059921403771</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html' ref='tag:blogger.com,1999:blog-2914337944584630860.post-3863294902058662222' source='http://www.blogger.com/feeds/2914337944584630860/posts/default/3863294902058662222' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2914337944584630860.post-6878044402242568759</id><published>2008-11-05T16:40:00.000-08:00</published><updated>2008-11-05T16:40:00.000-08:00</updated><title type='text'>I'm just giving this a random shot.I am looking to...</title><content type='html'>I'm just giving this a random shot.&lt;BR/&gt;&lt;BR/&gt;I am looking to find information on Sagwatch.net&lt;BR/&gt;&lt;BR/&gt;It is an anonymous, privately registered blog that posts smack about the Screen Actors Guild.&lt;BR/&gt;&lt;BR/&gt;I am trying to find any information I can regarding the registrar, the geographical location of the blog, etc.&lt;BR/&gt;&lt;BR/&gt;If you can't help me, can you point me in the right direction?&lt;BR/&gt;&lt;BR/&gt;Thanks!&lt;BR/&gt;&lt;BR/&gt;Tommy Landreu</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/6878044402242568759'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/6878044402242568759'/><link rel='alternate' type='text/html' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html?showComment=1225932000000#c6878044402242568759' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html' ref='tag:blogger.com,1999:blog-2914337944584630860.post-3863294902058662222' source='http://www.blogger.com/feeds/2914337944584630860/posts/default/3863294902058662222' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2914337944584630860.post-5759772990350312213</id><published>2008-08-12T10:44:00.000-07:00</published><updated>2008-08-12T10:44:00.000-07:00</updated><title type='text'>If the DNS server is running on the OpenBSD box or...</title><content type='html'>If the DNS server is running on the OpenBSD box or not you should be able to increase the source port randomization with NAT. By&lt;BR/&gt; default NAT using Pf will use source ports 49152 to 65535. This will show a ~4900 port standard deviation using kaminsky's tool. You can increase the source port pool by adding "port 1024:65535" to the end of your NAT line in pf.conf. This will easily increase the standard deviation to over 20K. If it helps we have a full explanation and example at Calomel.org https://calomel.org/pf_config.html</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/5759772990350312213'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/5759772990350312213'/><link rel='alternate' type='text/html' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html?showComment=1218563040000#c5759772990350312213' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html' ref='tag:blogger.com,1999:blog-2914337944584630860.post-3863294902058662222' source='http://www.blogger.com/feeds/2914337944584630860/posts/default/3863294902058662222' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2914337944584630860.post-8964071996607861989</id><published>2008-07-30T09:55:00.000-07:00</published><updated>2008-07-30T09:55:00.000-07:00</updated><title type='text'>How can others help your suit? Comcast is not a go...</title><content type='html'>How can others help your suit? &lt;BR/&gt;Comcast is not a good company. They break a lot of rules, and do not play fair.  Just look at their previous owners "Adelphia." &lt;BR/&gt;&lt;BR/&gt;Let us know how others can help.&lt;BR/&gt;&lt;BR/&gt;mr</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/8964071996607861989'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/8964071996607861989'/><link rel='alternate' type='text/html' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html?showComment=1217436900000#c8964071996607861989' title=''/><author><name>Michael</name><uri>http://www.blogger.com/profile/01751150440039436859</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html' ref='tag:blogger.com,1999:blog-2914337944584630860.post-3863294902058662222' source='http://www.blogger.com/feeds/2914337944584630860/posts/default/3863294902058662222' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2914337944584630860.post-547365853816161562</id><published>2008-07-27T18:01:00.000-07:00</published><updated>2008-07-27T18:01:00.000-07:00</updated><title type='text'>"If I am mistaken in any of my assumptions or sugg...</title><content type='html'>"If I am mistaken in any of my assumptions or suggestions, I would love to hear differently."&lt;BR/&gt;&lt;BR/&gt;Let's play with that.&lt;BR/&gt;&lt;BR/&gt;'I would love to hear differently, If I am mistaken in any of my assumptions or suggestions'&lt;BR/&gt;&lt;BR/&gt;So, if you are mistaken, you would like to hear otherwise? :]&lt;BR/&gt;&lt;BR/&gt;/pedant</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/547365853816161562'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/547365853816161562'/><link rel='alternate' type='text/html' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html?showComment=1217206860000#c547365853816161562' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html' ref='tag:blogger.com,1999:blog-2914337944584630860.post-3863294902058662222' source='http://www.blogger.com/feeds/2914337944584630860/posts/default/3863294902058662222' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2914337944584630860.post-15448264398766915</id><published>2008-07-26T20:08:00.000-07:00</published><updated>2008-07-26T20:08:00.000-07:00</updated><title type='text'>@Dan Kaminsky:The results look good.  Previously, ...</title><content type='html'>@Dan Kaminsky:&lt;BR/&gt;&lt;BR/&gt;The results look good.  Previously, the DNS-OARC tests were showing me as good whereas yours was not.  Now it seems to correctly detect my mitigation steps:&lt;BR/&gt;&lt;BR/&gt;bf0d8ea5035e.doxdns5.com:&lt;BR/&gt;208.127.144.14:61831 TXID=4821&lt;BR/&gt;208.127.144.17:52716 TXID=11826&lt;BR/&gt;208.127.144.19:59798 TXID=27644&lt;BR/&gt;208.127.144.20:53650 TXID=3141&lt;BR/&gt;208.127.144.15:56428 TXID=18012</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/15448264398766915'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/15448264398766915'/><link rel='alternate' type='text/html' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html?showComment=1217128080000#c15448264398766915' title=''/><author><name>Jon Hart</name><uri>http://www.blogger.com/profile/03410754059921403771</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html' ref='tag:blogger.com,1999:blog-2914337944584630860.post-3863294902058662222' source='http://www.blogger.com/feeds/2914337944584630860/posts/default/3863294902058662222' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2914337944584630860.post-384606690635931593</id><published>2008-07-26T20:07:00.000-07:00</published><updated>2008-07-26T20:07:00.000-07:00</updated><title type='text'>@Anonymous:  This should work in either situation ...</title><content type='html'>@Anonymous:  &lt;BR/&gt;&lt;BR/&gt;This should work in either situation -- when the DNS server is on the same box as pf, or when the DNS server is "behind" pf.  You will obviously need to modify your interfaces and addresses to match your setup, however the URl that Steve provided   just prior to your comment has a more robust solution with regards to interfaces names and such.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/384606690635931593'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/384606690635931593'/><link rel='alternate' type='text/html' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html?showComment=1217128020000#c384606690635931593' title=''/><author><name>Jon Hart</name><uri>http://www.blogger.com/profile/03410754059921403771</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html' ref='tag:blogger.com,1999:blog-2914337944584630860.post-3863294902058662222' source='http://www.blogger.com/feeds/2914337944584630860/posts/default/3863294902058662222' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2914337944584630860.post-893065433530950843</id><published>2008-07-26T19:25:00.000-07:00</published><updated>2008-07-26T19:25:00.000-07:00</updated><title type='text'>Jon,   Thanks for the good words.  Can you test no...</title><content type='html'>Jon,&lt;BR/&gt;&lt;BR/&gt;   Thanks for the good words.  Can you test now on the script presently hosted at www.doxpara.com?  It should correctly detect randomness from you.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/893065433530950843'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/893065433530950843'/><link rel='alternate' type='text/html' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html?showComment=1217125500000#c893065433530950843' title=''/><author><name>Dan Kaminsky</name><uri>http://www.doxpara.com</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html' ref='tag:blogger.com,1999:blog-2914337944584630860.post-3863294902058662222' source='http://www.blogger.com/feeds/2914337944584630860/posts/default/3863294902058662222' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2914337944584630860.post-5608874153958716697</id><published>2008-07-22T03:46:00.000-07:00</published><updated>2008-07-22T03:46:00.000-07:00</updated><title type='text'>This doesn't work when the DNS-server is on the pf...</title><content type='html'>This doesn't work when the DNS-server is on the pf box itself, right?&lt;BR/&gt;&lt;BR/&gt;Doesn't seem to work for me.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/5608874153958716697'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/5608874153958716697'/><link rel='alternate' type='text/html' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html?showComment=1216723560000#c5608874153958716697' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html' ref='tag:blogger.com,1999:blog-2914337944584630860.post-3863294902058662222' source='http://www.blogger.com/feeds/2914337944584630860/posts/default/3863294902058662222' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2914337944584630860.post-1915924787771726486</id><published>2008-07-20T16:33:00.000-07:00</published><updated>2008-07-20T16:33:00.000-07:00</updated><title type='text'>Stuart Henderson helpfully posted this suggestion ...</title><content type='html'>Stuart Henderson helpfully posted this suggestion to misc@ the day after the DNS vuln was announced.  Anyone reading misc should already be covered.&lt;BR/&gt;&lt;BR/&gt;http://marc.info/?l=openbsd-misc&amp;amp;m=121561002720622&amp;amp;w=2</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/1915924787771726486'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/1915924787771726486'/><link rel='alternate' type='text/html' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html?showComment=1216596780000#c1915924787771726486' title=''/><author><name>Steve</name><uri>http://www.blogger.com/profile/06779020054285806710</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html' ref='tag:blogger.com,1999:blog-2914337944584630860.post-3863294902058662222' source='http://www.blogger.com/feeds/2914337944584630860/posts/default/3863294902058662222' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-2914337944584630860.post-2549935486052900292</id><published>2008-07-16T10:05:00.000-07:00</published><updated>2008-07-16T10:05:00.000-07:00</updated><title type='text'>Michael Rash over at Cipherdyne has written a simi...</title><content type='html'>Michael Rash over at &lt;A HREF="http://www.cipherdyne.org" REL="nofollow"&gt;Cipherdyne&lt;/A&gt; has written a &lt;A HREF="http://www.cipherdyne.org/blog/2008/07/mitigating-dns-cache-poisoning-attacks-with-iptables.html" REL="nofollow"&gt;similar article&lt;/A&gt; that talks about mitigating this vulnerability using Linux's iptables.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/2549935486052900292'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2914337944584630860/3863294902058662222/comments/default/2549935486052900292'/><link rel='alternate' type='text/html' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html?showComment=1216227900000#c2549935486052900292' title=''/><author><name>Jon Hart</name><uri>http://www.blogger.com/profile/03410754059921403771</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.spoofed.org/2008/07/mitigating-dns-cache-poisoning-with-pf.html' ref='tag:blogger.com,1999:blog-2914337944584630860.post-3863294902058662222' source='http://www.blogger.com/feeds/2914337944584630860/posts/default/3863294902058662222' type='text/html'/></entry></feed>