republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » domain-tcp
Search Topic:
Uniqs:
169
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Making the user a member of "Users" group to preve »
« When is enough enough?  
AuthorAll Replies


normanzhang

join:2004-09-03
Calgary, AB
 domain-tcp

I'm seeing some domain-tcp from my LAN (workstations) to DNS. Workstations are suppose to do domain-udp for nslookup and not domain-tcp. Does this mean these boxes are infected with trojan?

B
Premium,MVM
join:2000-10-28


Sounds like quite a leap to me.

The last time this came up, it seemed that DNS queries can be EITHER TCP or UDP, depending in part on the size of the query packets. Or something like that. Google would likely tell all.

-- B
--
In a realm outside causality and function


wintr

join:2004-10-13
Calgary, AB
reply to normanzhang
I belive DNS uses both tcp and udp. But I'm not qualified to speak on this one.
--
546f6f206d616e792073656372657473»augmentedreality.ca


PetePuma
How many lumps do you want
Premium,MVM
join:2002-06-13
Arlington, VA
reply to normanzhang
DNS tries to use UDP, but will use TCP for any query returns that exceed the size of a single UDP packet. Both are necessary for a functional DNS system.


normanzhang

join:2004-09-03
Calgary, AB
Thanks for the clarification. I'd always thought TCP is for domain transfer, and UDP is for domain lookup.


Daniel
Premium,MVM
join:2000-06-26
Pleasanton, CA
clubs:


2 edits
reply to normanzhang
said by PetePuma See Profile:


DNS tries to use UDP, but will use TCP for any query returns that exceed the size of a single UDP packet. Both are necessary for a functional DNS system.
Nearly correct. In fact any DNS traffic that exceeds 512 bytes in size will move from UDP as its transport to TCP. Zone Transfers use TCP because they are usually above this limit.
--
cat knowledge | grep understanding

B
Premium,MVM
join:2000-10-28

So just querying on www.ANameLongerThanFiveHundredCharactersIncludingDNSOverheadANameLongerThanFiveHundred Charac tersIncludingDNSOverheadANameLongerThanFiveHundredCharactersIncludingDNSOverheadAN ameLongerT hanFiveHundredCharactersIncludingDNSOverheadANameLongerThanFiveHundredCharactersIn cludingDNS OverheadANameLongerThanFiveHundredCharactersIncludingDNSOverheadANameLongerThanFiv eHundredCh aractersIncludingDNSOverheadWhyAreYouStillReadingThisANameLongerThanFiveHundredCha ractersInc ludingDNSOverheadANameLongerThanFiveHundr.com

would generate a TCP session from the client side?

-- B
--
In a realm outside causality and function


Daniel
Premium,MVM
join:2000-06-26
Pleasanton, CA
clubs:


1 edit
said by B See Profile:

So just querying on www.ANameLongerThanFiveHundredCharactersIncludingDNSOverheadANameLongerThanFiveHundred Charac tersIncludingDNSOverheadANameLongerThanFiveHundredCharactersIncludingDNSOverheadAN ameLongerT hanFiveHundredCharactersIncludingDNSOverheadANameLongerThanFiveHundredCharactersIn cludingDNS OverheadANameLongerThanFiveHundredCharactersIncludingDNSOverheadANameLongerThanFiv eHundredCh aractersIncludingDNSOverheadWhyAreYouStillReadingThisANameLongerThanFiveHundredCha ractersInc ludingDNSOverheadANameLongerThanFiveHundr.com

would generate a TCP session from the client side?
That's correct, sir (assuming that's 512 bytes).
--
cat knowledge | grep understanding


wintr

join:2004-10-13
Calgary, AB

But the domain wouldn't have to be 512 in length to force it, since there is overhead for the frame and what not.

Right?
--
546f6f206d616e792073656372657473»augmentedreality.ca


Daniel
Premium,MVM
join:2000-06-26
Pleasanton, CA
clubs:
Yeah, I think you're right. I think it goes by the size of the packet in its entirety, not just the DNS payload itself. My bad.
--
cat knowledge | grep understanding


normanzhang

join:2004-09-03
Calgary, AB
From what I gathered, I would need to allow domain-tcp both ways for all hosts. As long as I setup DNS not to allow transfer of domain to others, then I'm fine?

ghost16825
Use security metrics
Premium
join:2003-08-26

reply to normanzhang
I asked the question »[Kerio 2.x] DNS over TCP a while ago as to whether anyone had ever experienced this happening as part of their day to day behaviour. I may have had this occur maybe once when using my PC over its entire lifetime. I've come to the conclusion that this is so rare it is not worth allowing as a firewall rule. If you ask me, you should just allow UDP for DNS requests and let that be the end of it.

Even with weird and wonderful domain names it's difficult to do.
Forums » Up and Running » Security » SecurityMaking the user a member of "Users" group to preve »
« When is enough enough?  


Saturday, 28-Nov 10:09:55 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [121] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [72] TiVo Sees Record Customer Losses
· [69] In-Flight Internet Headed For Bumpy Landing?
· [69] Verizon CEO: Hulu Will Be Dead Soon
· [62] Thanksgiving Open Thread
· [54] Weekend Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· Backstab vs screws (not which to use) [Home Repair & Improvement]
· Motion Sickness Solutions? [General Questions]
· Using AirMax to provide triple play services? [Wireless Service Providers]
· [Vista] Why is HD So Full? [Microsoft Help]
· What is the spell hit cap for a lvl 80 full arcane spec mage [World of Warcraft]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Hosts file attributes set to system and hidden [Security]
· Is Gear Score now the new requirement to get pug invite? [World of Warcraft]
· [Extreme Plus] Issues hosting on Xbox Live [Rogers]