DS Forums

 
 

DNS Spoofability of UK mobile operators


Reply
Thread Tools Search this Thread
Old 29-11-2010, 22:02
Thine Wonk
Forum Member
 
Join Date: Mar 2009
Posts: 14,545

So I thought I'd test the nameservers of some of the UK mobile operators to see how secure their DNS is and whether steps are in place to stop hackers injecting fake DNS records into the cache, this could be for bad / viral sites etc.

The results of the networks I can test are:

O2 - Excellent

3 - Excellent

T-mobile - Very bad

So this means that if you are on T-mobile / Virgin you are vulnerable to DNS spoofing and the ISP could serve up a page which is different to the one you wanted, potentially with exploits or viruses.

Anybody that wants to test their own ISPs nameservers against this attack can do so here

This also confirms to us that although T-mobile and 3 share cell sites and cell broadcast, that the back end networks are very different.

It was Dan Kaminsky a security researcher that found that this exploit was possible back in 2008 and warned sys admins to update their DNS security. I find it very surprising that T-mobile are vulnerable to this, looking at the pattern it looks to me like you could predict the source port and attempt to poison the cache.
Thine Wonk is offline   Reply With Quote
Please sign in or register to remove this advertisement.
Old 30-11-2010, 01:25
Appleseed
Forum Member
 
Join Date: Sep 2006
Location: Norfolk
Posts: 3,673
Christ you must be bored.
Appleseed is offline Follow this poster on Twitter   Reply With Quote
Old 30-11-2010, 07:34
Knighton
Inactive Member
 
Join Date: Oct 2009
Location: Space
Posts: 634
Christ you must be bored.
lol post of the year
Knighton is offline   Reply With Quote
Old 30-11-2010, 09:27
Thine Wonk
Forum Member
 
Join Date: Mar 2009
Posts: 14,545
Not really, it only takes a few minutes and I'd rather know how secure my service provider is, is also part of learning for me too. Testing and trying things and researching rather than just making it up and posting it as fact like a lot of people here do.
Thine Wonk is offline   Reply With Quote
Old 30-11-2010, 09:53
prking
Forum Member
 
Join Date: Sep 2002
Location: Weston-super-Mare
Posts: 9,167
Or doing a quick google and becoming a sudden expert!
prking is offline   Reply With Quote
Old 30-11-2010, 10:28
Thine Wonk
Forum Member
 
Join Date: Mar 2009
Posts: 14,545
Or doing a quick google and becoming a sudden expert!
Exactly, I work in IT and have a real practical experience, I have recognised IT qualifications and research things before I post them. All this is part of learning for me, occasionally I get it wrong, but most of the stuff I post is part of learning and research, rather than the marketing they read.

If I comment on mobile coverage I do it based on looking at coverage maps, reading articles, testing things however sad that may sound to some.

Others just post 'ear, in my front bedroom I get 3 bars and at work I get 2 bars so it must be the network with the best coverage'
Thine Wonk is offline   Reply With Quote
Old 03-12-2010, 00:22
corona
Forum Member
 
Join Date: Dec 2003
Posts: 145
it is good to know, Thanks
corona is offline   Reply With Quote
 
Reply




 
Forum Jump


All times are GMT. The time now is 13:02.