Windows Phone Thoughts - Daily News, Views, Rants and Raves

Check out the hottest Windows Mobile devices at our Expansys store!


Digital Home Thoughts

Loading feed...

Laptop Thoughts

Loading feed...

Android Thoughts

Loading feed...




Go Back   Thoughts Media Forums > WINDOWS PHONE THOUGHTS > Windows Phone News

Reply
 
Thread Tools Display Modes
  #1  
Old 07-29-2008, 07:00 PM
Ed Hansberry
Contributing Editor Emeritus
Ed Hansberry's Avatar
Join Date: Aug 2006
Posts: 8,228
Default Has Your Cellular Provider Patched Their DNS Servers?

http://www.dnsstuff.org

I am sure most of you by now are at least aware of the DNS Poisoning vulnerability that affects all DNS servers around the world, and where many vendors, including Microsoft, Cisco and Redhat, released patches to their products on the same day in July before exploit code could be written. If you aren't aware of it, Wikipedia has a pretty good overview.

As of right now, over half of the worlds DNS servers have not been patched, even though their vendor has likely released an update, unless they run Mac OS-X Server.

One of the main reasons someone would use this exploit is to make you think you are on a secure and familiar site, like your banks website. If you typed www.mybank.com in your browser, your DNS server could actually be tricked into redirecting you to some server in Russia that looked exactly like your banks site, and your browser would still show www.mybank.com in the URL at the top. Because many of us access this information on our devices, we should be able to trust the DNS server our phone is using, which is usually provided by our cellular provider. I finally found a test that works on Windows Mobile devices. Head over to DNSStuff.com and run the "DNS Vulnerability Check" in the lower left. In order to get the button to be visible and work, you may have to put Pocket IE into "desktop" mode. I am pleased to say that T-Mobile USA got all Good and Great marks on each of the tests, at least on their DNS servers in Washington state.

If your provider fails the tests, you should contact them. You can also override the DNS entries in your internet connection settings to use the free DNS servers at OpenDNS.org.

__________________
text sig
 
Reply With Quote
  #2  
Old 07-29-2008, 08:35 PM
blazingwolf
Theorist
Join Date: Aug 2006
Posts: 303

Thanks for the heads up on this Ed. I checked Verizon Wireless in Virginia and they report Good for just about everything. The only exception being a great for Source port standard deviation.

My Verizon DSL is another matter. It shows poor for all source port tests. Maybe a cal to customer service is in order for this.
 
Reply With Quote
  #3  
Old 07-29-2008, 09:52 PM
rlobrecht
Thinker
rlobrecht's Avatar
Join Date: Aug 2006
Posts: 333

Thanks Ed. I just checked AT&T wireless (3G) in Houston, and everything is labeled as GOOD.
 
Reply With Quote
  #4  
Old 07-29-2008, 10:40 PM
Ed Hansberry
Contributing Editor Emeritus
Ed Hansberry's Avatar
Join Date: Aug 2006
Posts: 8,228

Quote:
Originally Posted by blazingwolf View Post
My Verizon DSL is another matter. It shows poor for all source port tests. Maybe a cal to customer service is in order for this.
I'd be switching my home router to OpenDNS.org in about 2 seconds on that deal. I switched to OpenDNS.org a few months ago because I could block sites (adware, porn, etc) from ever entering my home LAN. The side benefit is I don't care if my cable provider is on top of things on patching their DNS servers. OpenDNS.org was one that worked closely with the industry to get this patched fast.
__________________
text sig
 
Reply With Quote
  #5  
Old 07-30-2008, 12:08 AM
blazingwolf
Theorist
Join Date: Aug 2006
Posts: 303

Quote:
Originally Posted by Ed Hansberry View Post
I'd be switching my home router to OpenDNS.org in about 2 seconds on that deal. I switched to OpenDNS.org a few months ago because I could block sites (adware, porn, etc) from ever entering my home LAN. The side benefit is I don't care if my cable provider is on top of things on patching their DNS servers. OpenDNS.org was one that worked closely with the industry to get this patched fast.
Done.

Thanks again for this. Very timely info that is coming in very useful for me.
 
Reply With Quote
  #6  
Old 08-05-2008, 07:23 PM
Phillip Dyson
Mystic
Join Date: Aug 2006
Posts: 1,520

Quote:
Originally Posted by Ed Hansberry View Post
I'd be switching my home router to OpenDNS.org in about 2 seconds on that deal.
I would like to do this. I've actually already created an account. I have a Linksys G router and noticed a DNS service that can be enabled. Is this where I would configure it to use OpenDNS.org?

Also, would I install the dynamic update client to one of my PCs or is there some way to set that up in the router?

thanks
__________________

Phone: Nexus one Backup Phone: AT&T Samsung Jack; Future Phone: I'm Watching WP7; Media Player: Platinum Zune HD 32GB; Home Server: HP MediaSmart Server LX195 Console: XBox 360, PS3, Wii
 
Reply With Quote
  #7  
Old 08-05-2008, 11:32 PM
Ed Hansberry
Contributing Editor Emeritus
Ed Hansberry's Avatar
Join Date: Aug 2006
Posts: 8,228

Quote:
Originally Posted by Phillip Dyson View Post
I would like to do this. I've actually already created an account. I have a Linksys G router and noticed a DNS service that can be enabled. Is this where I would configure it to use OpenDNS.org?

Also, would I install the dynamic update client to one of my PCs or is there some way to set that up in the router?

thanks
I have a Lynksys G as well. On the initial page where you can type in the DNS servers, type in the OpenDNS.org dns server addresses. If you only wnat to use their DNS services, your done. If you want to use their filtering services, like blocking porn or adware sites, you'll need to do a few more steps.

On the DDNS page, you'll need to get a Dynamic DNS number. I use DynDNS.org - which you'll need an account for. This is so OpenDNS can find your IP address. I then use a program called OpenDNS Updater at http://blog.opendns.com/2007/09/07/m...ic-ip-updater/ that can communicate with OPenDNS.org periodically.

It took me about 20 minutes to sign up for everything and get it all working, but now that I have, it is trouble free, and free of cost as well.
__________________
text sig
 
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 07:39 PM.