BugTraq
Has anyone implemented "double forward DNS"? Aug 30 2008 12:05AM
Duncan Simpson (dps simpson demon co uk) (5 replies)

Double reverse DNS, which checks the name found using reverse DNS matches the
IP adrdess enquired about is now common. I was wondering wether about has
applied the same technique to forward DNS queries too.

The idea here is that a client that finds www.example.com is 192.168.3.42 does
not trist this infiormation. Instead it looks up 42.3.168.192.in-addr.arpa and
checks for a PTR record saying www.example.com. If one is not found then the
result is disinformation and should not be used. Of course if the bad guy also
controls the client's information about the reverse zone it still loses.

The major problem I can see is that there might that hosts in ISP's
dynamically allocated address pools might all fail double forward DNS checks.
OTOH if you were expecting your bank or a CA's server that might count as a
feature :-)

Browsers could implement this *now* and hopefully sreject at least some DNS
disinformation.

It would also help if web browser's displayed the information about who a
valid certifciate correspnonds to somewhere prominently instead of just a
padlock. My evil ID and banking detials theft site could have a valid
cetificate and therefore fool users who just check for a valid SSL certificate.

--
Duncan (-:
"software industry, the: unique industry where selling substandard goods is
legal and you can charge extra for fixing the problems."

[ reply ]
Re: Has anyone implemented "double forward DNS"? Sep 03 2008 04:40PM
Jerry Franz (jfranz freerun com)
Re: Has anyone implemented "double forward DNS"? Sep 03 2008 07:46AM
terry white (twhite aniota com)
Re: Has anyone implemented "double forward DNS"? Sep 03 2008 03:42AM
The Fungi (fungi yuggoth org)
Re: Has anyone implemented "double forward DNS"? Sep 03 2008 12:25AM
Glynn Clements (glynn gclements plus com)
Re: Has anyone implemented "double forward DNS"? Sep 02 2008 11:59PM
Ansgar Wiechers (bugtraq planetcobalt net) (1 replies)
Re: Has anyone implemented "double forward DNS"? Sep 04 2008 01:34PM
Ansgar -59cobalt- Wiechers (bugtraq planetcobalt net) (1 replies)
Re: Has anyone implemented "double forward DNS"? Sep 05 2008 09:11AM
Steven Bakker (steven bakker ams-ix net)


 

Privacy Statement
Copyright 2010, SecurityFocus