Search:  

 
 
   News
newer
story category Comcast Quickly Tackled New DNS Threat
Contrary to some online tests of their networks...
09:56AM Friday Jul 25 2008 by Karl Bode
tags: business · security · Comcast
Yesterday I noted that with two working exploits in the wild for a major new DNS vulnerability, a significant number of major ISPs had yet to fully patch their systems, leaving their users vulnerable to scams and identity theft. While some security analyst tests claimed that Comcast was among the companies falling behind in the patching, Comcast tells me that isn't the case.

Comcast spokesman Charlie Douglas says the company had their systems patched back in June -- and have been working hard to ensure all fixes are in place. Dan Kaminsky, the researcher who first discovered this flaw, confirms this with a post to our forums, where he notes Comcast has worked with a company named Nominum to implement a system that can slow the discovered attack down by a "couple hundred times."

"A couple hundred times harder to attack corresponds to ~8 bits of entropy, which is how short they are right now," he says. "They're investigating now if they can get a couple of bits more in, just for added security." Kaminsky says this is an instance where Comcast earned some well-deserved kudos.

"Nominum, and ComCast by extension, need some credit for working to develop more intensive protections against this attack -- even if it's much less convenient for those of us building test tools," says Kaminsky. "It's not every day that Comcast and I are on the same side of the fence -- ahem, net neutrality. This is however a much graver threat, and frankly more ISP's need to follow Comcast's lead here (now there are words I never thought I'd write!)."

Update:A user writes in to note that Verizon may also be falsely accused of being slow to patch their systems:
The DNS servers listed as Verizon servers at HackerFactor are, in fact, the sole property of Level (3). They are improperly using the gtei.net domain name and that issue is being investigated. Verizon is also running Nominum software and the Verizon DNS servers were proactively updated to mitigate the DNS cache poisoning exploit. Level (3) and Level (3) alone is responsible for the servers 4.2.2.1 - 4.2.2.6.

Related:
  1. Comcast Domain Hackers Speak
  2. Comcast Successfully Delays Philly FiOS
  3. Philly FiOS Feud Gets Uglier
  4. Can Spam Act Celebrates Five Years Of Ineffectiveness
  5. 37% Of Malware Originates In U.S.
  6. Comcast Mum On New Bandwidth Tracker
  7. New Comcast Throttling System 100% Online
  8. ISPs Won't Admit Participation In New RIAA Plan
Forums » Comcast Quickly Tackled New DNS Threat
view: topics flat text 
Post a:
questionable

join:2005-10-18
Phoenix, AZ

edit:
July 25th, @09:57AM

omg

Watch out Karl some might say you have gone soft on Comcast... Next thing we will know is your in a pub drinking with Roadrunner Rick

Smith6612
Premium
join:2008-02-01
united state

Re: omg

He's Comcast Rick I believe. If you look at his avatar, an anvil is smashing the RR and Comcast is coming in.

sousademiami

join:2003-02-04
Miami, FL

edit:
July 25th, @10:06AM

What?

Why are you always trashing Comcast every chance you get? You never publish anything positive about Comcast, it's so UNFAIR!
--
OASAASLLS

Smith6612
Premium
join:2008-02-01
united state

Re: What?

This is positive news towards Comcast. Karl did not trash Comcast on this one.

sousademiami

join:2003-02-04
Miami, FL
·Comcast
·AT&T Southeast

Re: What?

said by Smith6612 See Profile :

This is positive news towards Comcast. Karl did not trash Comcast on this one.
Sorry for my poor use of sarcasm.

Pingmeister



Re: What?

said by sousademiami See Profile :

said by Smith6612 See Profile :

This is positive news towards Comcast. Karl did not trash Comcast on this one.
Sorry for my poor use of sarcasm.
I was with you %100 It worked

Smith6612
Premium
join:2008-02-01
united state
I have a hard time of recognising sarcasm online >.>
battleop

join:2005-09-28
00000
There are often positive editorials about Comcast on the front page. The sad thing is that the front page editorials usually include some sort of bash that is totally unrelated to the positive editorial.
brianiscool

join:2000-08-16
Miami, FL

hah

Comcast would loose cash on redirection that is why they patched this DNS issue so quickly

TK Junk Mail
Go ahead, make my day
Premium
join:2002-03-03
Margate City, NJ
clubs:
·Comcast

Re: hah

said by brianiscool See Profile :

Comcast would loose cash on redirection that is why they patched this DNS issue so quickly
And how would they lose cash?

1 - If their DNS servers were cache poisoned by this exploit it could cost their users some money if their identities were stolen when going to their online banking accounts and were misdirected to a phishing page. It wouldn't cost Comcast anything.

2 - Comcast doesn't run a redirection service to their own search page with ads when a user mistypes a domain name. So no money lost there.

So maybe you could enlighten us on how they would have lost money by not patching this flaw.
--
My BLOG .. .. Internet News .. .. My Web Page
Ask yourself one question: 'Do I feel lucky?' Well, do ya punk?
brianiscool

join:2000-08-16
Miami, FL

Re: hah

stop poisoning our minds

ptrowski
Got Helix?
Premium
join:2005-03-14
Putnam, CT
clubs:
·Metrocast Communic..
·AT&T DSL Service
·VOIPo
·ViaTalk

Re: hah

said by brianiscool See Profile :

stop poisoning our minds
Care to respond to TK Junk Mail? I would like to know how they are "losing cash" as you put it.
--
"A religious war is like children fighting over who has the strongest imaginary friend."

Have you been touched by his noodly appendage? »www.venganza.org

punker
deleted by moderator
Premium
join:2004-06-21
Palmdale, CA
clubs:
·Time Warner Cable
·Time Warner VOIP
·RoadRunner Cable

said by TK Junk Mail See Profile :

said by brianiscool See Profile :

Comcast would loose cash on redirection that is why they patched this DNS issue so quickly
And how would they lose cash?

1 - If their DNS servers were cache poisoned by this exploit it could cost their users some money if their identities were stolen when going to their online banking accounts and were misdirected to a phishing page. It wouldn't cost Comcast anything.

2 - Comcast doesn't run a redirection service to their own search page with ads when a user mistypes a domain name. So no money lost there.

So maybe you could enlighten us on how they would have lost money by not patching this flaw.
they will get sued
jester121

join:2003-08-09
Lake Zurich, IL
·ViaTalk

I do not wish to enter a subject

The most interesting news out of this entire series of events was that Level 3 indicated they are going to restrict access to their 4.2.2.x DNS servers at some point in the future.

That's going to be an interesting day for sure -- those addresses have been a crutch for lazy admins for years and I bet they're buried in millions of configs that have no business using them.
NormanS
Premium,MVM
join:2001-02-14
San Jose, CA
·Pacific Bell - SBC

Re: I do not wish to enter a subject

That may have already begun. Level 3 uses "Anycast" on their DNS servers, and I noticed a hard failure on 4.2.2.1 once. Anycast means that you don't always reach the same server, so your results can be variable. This is obvious with the ATTIS DNS servers, which also use Anycast, and sometimes fail the DNS vulnerability test, but other times pass.
--
Norman
~Oh Lord, why have you come
~To Konnyu, with the Lion and the Drum

dadkins
Go For It
Premium,MVM
join:2003-09-26
Hercules, CA
·Comcast

Added a third DNS too!

Mine...

68.87.76.178
68.87.78.130
... and now a third:
68.87.69.146

Seen here:
»Comcast added additional DNS server
--
Think outside the Fox... Opera

ztmike
Premium
join:2001-08-02
Michigan City, IN

OpenDNS ?

Has OpenDNS been patched? I stay FAR away from Comcast's DNS servers.
--
WhY sO SeRiOUs!?
iansltx

join:2007-02-19
Fredericksburg, TX

Re: OpenDNS ?

Yes, they were patched from the start actually.

jgkolt
Premium
join:2004-02-21
Lakewood, OH
clubs:

Re: OpenDNS ?

how can you check to see if your dns was patched. DO you have a link?
iansltx

join:2007-02-19
Fredericksburg, TX

Re: OpenDNS ?

It's in the main body of the article, DoxPara.net off the top of my head.

jubangy
Premium
join:2005-03-26
Erie, PA
Actually their comment was that they were never vulnerable to this problem and did not need patched.

punker
deleted by moderator
Premium
join:2004-06-21
Palmdale, CA
clubs:

edit:
July 25th, @03:35PM

TWC patch has Failed

last time twc try to patch there DNS servers stop working

and it does have the vulnerability

Your name server, at 66.75.164.90, appears vulnerable to DNS Cache Poisoning.
All requests came from the following source port: 38581
Forums » Comcast Quickly Tackled New DNS Threat


Friday, 09-Jan 01:21:15 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2009 dslreports.com.