Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Streamyx Streamyx Slowdown due to DNS Servers Patching?, Patching of DNS Cache Poisoning ;)

views
     
TScybpsych
post Aug 1 2008, 07:45 PM, updated 18y ago

---------------------
*********
All Stars
65,295 posts

Joined: Jan 2003
It started from here: http://www.doxpara.com/ ... use the built-in test on the DNS. .. I've tested it last week, our TMnet's DNS servers are affected ... as of now, it's partially patched! thumbup.gif

More tests >> http://3db973cc9d6d630eff58c602.et.dns-oarc.net/

More! >> http://member.dnsstuff.com/tools/vu800113.php


it's been a very *hot* topic for the past few weeks! Since Patch Tuesday this month by Microsoft, it's only been made aware by the common public. Remember MS hotfix KB951748 and causes havoc to your firewall (especially Zonealarm)? MS and other vendors have coordinated their patching to fix the DNS servers!

Read the blogs/postings!


Hopefully, TMnet restore the full functionality of our bandwidth/DNS!!

I't darn slow surfing!
Turnip
post Aug 1 2008, 07:56 PM

bonjour beau là-bas
******
Senior Member
1,111 posts

Joined: Aug 2005
From: UK


QUOTE(cybpsych @ Aug 1 2008, 08:45 PM)
It started from here: http://www.doxpara.com/ ... use the built-in test on the DNS. .. I've tested it last week, our TMnet's DNS servers are affected ... as of now, it's partially patched!  thumbup.gif

More tests >> http://3db973cc9d6d630eff58c602.et.dns-oarc.net/

More! >> http://member.dnsstuff.com/tools/vu800113.php
it's been a very *hot* topic for the past few weeks! Since Patch Tuesday this month by Microsoft, it's only been made aware by the common public. Remember MS hotfix KB951748 and causes havoc to your firewall (especially Zonealarm)? MS and other vendors have coordinated their patching to fix the DNS servers!

Read the blogs/postings!
Hopefully, TMnet restore the full functionality of our bandwidth/DNS!!

I't darn slow surfing!
*
no wonder i got kicked frequently from online gaming sweat.gif
flee93
post Aug 1 2008, 07:56 PM

Getting Started
**
Junior Member
94 posts

Joined: Jul 2007


Huh?
DJFoo000
post Aug 1 2008, 08:01 PM

Really? That's the best reply you can come up with?
*******
Senior Member
3,000 posts

Joined: Sep 2005
From: Puchong, Selangor



how long does it take to complete the patching? I'm cursing TMNut like nobody's business since yesterday.
TScybpsych
post Aug 1 2008, 08:31 PM

---------------------
*********
All Stars
65,295 posts

Joined: Jan 2003
let me put it in a simpler terms...

1) When you type an address, e.g. www.google.com, it's being translated to IP address, e.g. 72.14.233.32. Remember, Net "true" addresses are always in IP address.

www.google.com = domain name [easier to remember this, right?]
72.13.233.32 = IP address [who ever can remember each IPs for all the URLs in a bookmark?! doh.gif]

2) Each ISP, e.g. TMnet, has 2 DNS (Domain Name Server) servers. 1 is main and another is redundancy. TMnet's DNS server IPs are 202.188.0.132 and 202.188.1.28.

3) www.google.com -(query)-> DNS -(reply)-> IP address. The DNS is the domain name translator.

4) Each DNS reply (source) always tied to a source port # (0-65535 only) and query ID (QID).

5) Malicious ppl sends out many fake/invalid queries to your DNS server so that it can "guess" what's the next port/QID that follows. Once it's able to guess a specific port and QID for each "query", he/she 'poison' the DNS cache (buffer) and marked it to active for a specific period of time or simply forever!

6) Imagine this: If I poison the DNS cache for www.google.com = 42.16.33.154 (e.g. a link to phishing site, po*n site or hoax page)...

7) The next time you enter www.google.com in your browser (IE, FF, etc.), it'll point to different place! This is because the DNS servers have been 'poisoned' to point to different IP address!

8) What the patching does is to "randomize" the source port # and QID for each IP address replies. This makes it difficult for malicious ppl to guess.


Read the good analogy at Doxpara.com ... it explains how malicious ppl do the 'guessing' and 'poisoning'!

Of course my explanation above is just a crude way explaining this DNS Cache Poison vulnerability. sweat.gif

This post has been edited by cybpsych: Aug 1 2008, 08:41 PM
dafreak
post Aug 1 2008, 10:01 PM

Regular
******
Senior Member
1,064 posts

Joined: Jul 2008
From: Star Stuff


i thought tmnet's DNS server is 202.188.1.5 and 202.188.0.133??
onscreen
post Aug 1 2008, 10:09 PM

Nomby
****
Senior Member
675 posts

Joined: Jan 2003
From: PJ, Selangor


TM should put the effort to post up an announcement in their site rather to have us USERS to figure out whats the problem behind.

Ya, i do predict that Streamyx suffered from this DNS "sickness" since the people over there love very-last-minute-repair-work.
rajulkabir
post Aug 1 2008, 11:07 PM

Regular
Group Icon
Elite
1,428 posts

Joined: Oct 2004


I don't see why patching the DNS servers would result in the general miserable service Streamyx has been providing this week - since the main problem has been dropped packets.
zariqcools
post Aug 2 2008, 10:17 AM

Kerr
*****
Senior Member
711 posts

Joined: Jun 2008


no wonder when i watched vid on youtube its so damn slow!!
=mie=
post Aug 2 2008, 04:04 PM

New Member
*
Junior Member
38 posts

Joined: Aug 2008
From: dungeon



dam..cant play wolfteam online.. always disconnect

 

Change to:
| Lo-Fi Version
0.0156sec    0.29    5 queries    GZIP Disabled
Time is now: 7th December 2025 - 09:57 PM