Broadband
Dial-Up
Email
Hosting
Wireless
Security
Useful Tools
Quick Reference
Contact Us
Customer Portal
Site Search

Zen Internet Support Forum

Welcome to the Zen Internet community support forums.

Before posting we recommend you search our
extensive Knowledge Base or the forum archives
as an answer to your query may already be available.

Welcome to Zen Internet Support Forum Sign in | Join | Help
in
Forums Forum Rules

Fundamental problems with DNS

Last post 21-08-2008, 10:15 AM by Bootlebarth. 3 replies.
Sort Posts: Previous Next
  •  09-07-2008, 5:36 PM 30929

    Fundamental problems with DNS

    Everybody should be aware that Dan Kaminsky has found an exploit for the known problem of insufficient randomisation in DNS queries.

    Right now Zen's servers (which recurse on behalf of most Zen customers) fail the Doxpara test.

    Is there a specific schedule for when Zen will be applying the relevant patches and making this problem go away for its users?

    What is Zen doing to support adoption of DNSSEC (which is probably the only permanent fix for such problems) in .UK and in the root?

  •  10-07-2008, 9:09 AM 30935 in reply to 30929

    Re: Fundamental problems with DNS

    We are part way thro' upgrading to the fixed version of BIND. We upgraded half the customer facing caches yesterday and the other half will be done today.

    As to DNSSEC, it's something we will be looking into in due course.


    --
    Jerry Nicholls
    Principal Systems Engineer
    perl -e '$_=q(print "perl -e \x27\$_=q($_);eval\x27\n");eval'
  •  10-07-2008, 11:49 PM 30938 in reply to 30935

    Re: Fundamental problems with DNS

    Jerry Nicholls:

    We are part way thro' upgrading to the fixed version of BIND. We upgraded half the customer facing caches yesterday and the other half will be done today.

     Ah yes, I see the test checks out OK now. Thanks for the prompt answer.

  •  21-08-2008, 10:15 AM 31385 in reply to 30938

    DNS server vulnerability

    Is there any news of the status of Zen's DNS servers. Does no news mean they are not patched and that users are vulnerable?
    Come on Boro
View as RSS news feed in XML