• TV
  • MOVIES
  • MUSIC
  • SHOWBIZ
  • SOAPS
  • GAMING
  • TECH
  • FORUMS
  • Follow
    • Follow
    • facebook
    • twitter
    • google+
    • instagram
    • youtube
Hearst Corporation
  • TV
  • MOVIES
  • MUSIC
  • SHOWBIZ
  • SOAPS
  • GAMING
  • TECH
  • FORUMS
Forums
  • Register
  • Login
  • Forums
  • Gadgets
  • Mobile Phones
DNS Spoofability of UK mobile operators
Thine Wonk
29-11-2010
So I thought I'd test the nameservers of some of the UK mobile operators to see how secure their DNS is and whether steps are in place to stop hackers injecting fake DNS records into the cache, this could be for bad / viral sites etc.

The results of the networks I can test are:

O2 - Excellent

3 - Excellent

T-mobile - Very bad

So this means that if you are on T-mobile / Virgin you are vulnerable to DNS spoofing and the ISP could serve up a page which is different to the one you wanted, potentially with exploits or viruses.

Anybody that wants to test their own ISPs nameservers against this attack can do so here

This also confirms to us that although T-mobile and 3 share cell sites and cell broadcast, that the back end networks are very different.

It was Dan Kaminsky a security researcher that found that this exploit was possible back in 2008 and warned sys admins to update their DNS security. I find it very surprising that T-mobile are vulnerable to this, looking at the pattern it looks to me like you could predict the source port and attempt to poison the cache.
Appleseed
30-11-2010
Christ you must be bored.
Knighton
30-11-2010
Originally Posted by Appleseed:
“Christ you must be bored.”

lol post of the year
Thine Wonk
30-11-2010
Not really, it only takes a few minutes and I'd rather know how secure my service provider is, is also part of learning for me too. Testing and trying things and researching rather than just making it up and posting it as fact like a lot of people here do.
prking
30-11-2010
Or doing a quick google and becoming a sudden expert!
Thine Wonk
30-11-2010
Originally Posted by prking:
“Or doing a quick google and becoming a sudden expert!”

Exactly, I work in IT and have a real practical experience, I have recognised IT qualifications and research things before I post them. All this is part of learning for me, occasionally I get it wrong, but most of the stuff I post is part of learning and research, rather than the marketing they read.

If I comment on mobile coverage I do it based on looking at coverage maps, reading articles, testing things however sad that may sound to some.

Others just post 'ear, in my front bedroom I get 3 bars and at work I get 2 bars so it must be the network with the best coverage'
corona
03-12-2010
it is good to know, Thanks
VIEW DESKTOP SITE TOP

JOIN US HERE

  • Facebook
  • Twitter

Hearst Corporation

Hearst Corporation

DIGITAL SPY, PART OF THE HEARST UK ENTERTAINMENT NETWORK

© 2015 Hearst Magazines UK is the trading name of the National Magazine Company Ltd, 72 Broadwick Street, London, W1F 9EP. Registered in England 112955. All rights reserved.

  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy
  • Complaints
  • Site Map