SAD DNS !

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
Redback813
DD-WRT Novice


Joined: 10 Nov 2015
Posts: 43

PostPosted: Mon Aug 23, 2021 23:31    Post subject: SAD DNS ! Reply with quote
I ran across an article about SAD DNS and it seem to be quiet a serious problem regardless of the O/S. The first weaponise network side channel attack that has serious security impacts. How does one defend against this on a router.


https://www.cs.ucr.edu/~zhiyunq/SADDNS.html

Test Result
Your DNS server IP is 19x.xx.xxx.xx
It seems your DNS server is running Linux > 3.18
Since it is running DNS software that uses sendto() on the outgoing socket, your DNS server is vulnerable regardless which OS it runs.
The test currently only takes the side channel port scanning vulnerability into consideration. A successful attack may also require other features in the server (e.g., supporting cache).
The test is conducted on 2021-08-23
Sponsor
mrjcd
DD-WRT Guru


Joined: 31 Jan 2015
Posts: 6291
Location: Texas

PostPosted: Tue Aug 24, 2021 0:19    Post subject: Reply with quote
EA8500 running r47225 is my main gateway router and your link tells me:

Your DNS server IP is 45.76.254.23
It seems your DNS server is running Linux > 3.18
Since it is running the vulnerable version of OS that has not been patched yet, your DNS server is vulnerable.
The test currently only takes the side channel port scanning vulnerability into consideration. A successful attack may also require other features in the server (e.g., supporting cache).
The test is conducted on 2021-08-23 23:57:16.723540685 UTC
Disclaimer: This test is not 100% accurate and is for test purposes only.

--------
enabled her 'Recursive DNS Resolving (Unbound)' and this is what it now says:
--------

Your DNS server IP is 96.46.xxx.xxx (that is my WAN IP)
Since it blocks outgoing ICMP packets, your DNS server is not vulnerable.
The test currently only takes the side channel port scanning vulnerability into consideration. A successful attack may also require other features in the server (e.g., supporting cache).
The test is conducted on 2021-08-24 00:05:10.159349107 UTC
Disclaimer: This test is not 100% accurate and is for test purposes only.

--------
I used to run unbound all time & don't really remember why I ever quit...guess we'll see how it does these days Twisted Evil
Redback813
DD-WRT Novice


Joined: 10 Nov 2015
Posts: 43

PostPosted: Tue Aug 24, 2021 1:23    Post subject: Reply with quote
mrjcd wrote:
EA8500 running r47225 is my main gateway router and your link tells me:
--------
enabled her 'Recursive DNS Resolving (Unbound)' and this is what it now says:
--------
Twisted Evil


Thanks, I'll give another go with unbound my self.
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum