Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > rocksolid.shared.security > #66 > unrolled thread
| Started by | Anonymous <poster@anon.com> |
|---|---|
| First post | 2021-01-20 05:30 -0800 |
| Last post | 2021-01-21 08:38 +0100 |
| Articles | 6 — 4 participants |
Back to article view | Back to rocksolid.shared.security
remote code exec in dnsmasq Anonymous <poster@anon.com> - 2021-01-20 05:30 -0800
Re: remote code exec in dnsmasq Marc SCHAEFER <schaefer@alphanet.ch> - 2021-01-20 16:00 +0100
Re: remote code exec in dnsmasq "AnonUser" <anonuser@rocksolidbbs.com.remove-32i-this> - 2021-01-20 18:47 +0000
Re: remote code exec in dnsmasq Guest <guest@retrobbs.rocksolidbbs.com> - 2021-01-20 13:25 -0500
Re: remote code exec in dnsmasq Marc SCHAEFER <schaefer@alphanet.ch> - 2021-01-21 08:40 +0100
Re: remote code exec in dnsmasq Marc SCHAEFER <schaefer@alphanet.ch> - 2021-01-21 08:38 +0100
| From | Anonymous <poster@anon.com> |
|---|---|
| Date | 2021-01-20 05:30 -0800 |
| Subject | remote code exec in dnsmasq |
| Message-ID | <opsec.767.1iv4v3@anon.com> |
https://www.jsof-tech.com/wp-content/uploads/2021/01/DNSpooq_Technical-Whitepaper.pdf CVE-2020-25681: Heap-based buffer overflow with arbitrary overwrite Thank fuck I am on tor and don't rely on DNS. -- Posted on def2
[toc] | [next] | [standalone]
| From | Marc SCHAEFER <schaefer@alphanet.ch> |
|---|---|
| Date | 2021-01-20 16:00 +0100 |
| Message-ID | <ru9gi5$el1$1@shakotay.alphanet.ch> |
| In reply to | #66 |
Anonymous <poster@anon.com> wrote: > Thank fuck I am on tor and don't rely on DNS. However, your IP router might well run dnsmasq.
[toc] | [prev] | [next] | [standalone]
| From | "AnonUser" <anonuser@rocksolidbbs.com.remove-32i-this> |
|---|---|
| Date | 2021-01-20 18:47 +0000 |
| Message-ID | <a5c363938980657088f898e6d9482201$1@retrobbs.i2p> |
| In reply to | #67 |
To: Marc SCHAEFER Is there a way to check which dns server software is being used? I mean other than having full login access to whatever it runs. -- Posted on RetroBBS retrobbs.i2p
[toc] | [prev] | [next] | [standalone]
| From | Guest <guest@retrobbs.rocksolidbbs.com> |
|---|---|
| Date | 2021-01-20 13:25 -0500 |
| Message-ID | <rua126$cic$1@def5.org> |
| In reply to | #68 |
>However, your IP router might well run dnsmasq. Yes, that is true. I consider my router to be compromised anyway, and don't trust it. I don't see though how this would compromise my tor setup. The authority tor nodes are hardcoded into tor (with their ip addresses), and everything after should be safe I think. I could be wrong of course. There was some way to use dns to deanomize tor users, but it worked differently (see : https://nakedsecurity.sophos.com/2016/10/05/unmasking-tor-users-with-dns/ ) >Is there a way to check which dns server software is being used? I mean other than having full login access to whatever it runs. If you can find out the system of your router, it should be easy to verify. Or you run the attack against your own router (bit more effort). -- Posted on def3
[toc] | [prev] | [next] | [standalone]
| From | Marc SCHAEFER <schaefer@alphanet.ch> |
|---|---|
| Date | 2021-01-21 08:40 +0100 |
| Message-ID | <rubb4k$vmp$1@shakotay.alphanet.ch> |
| In reply to | #69 |
Guest <guest@retrobbs.rocksolidbbs.com> wrote: > Yes, that is true. I consider my router to be compromised anyway, and don't trust it. If you have a firewall behind your router, protecting the router from accessing your internal network, then you are presumably safe, if using tor only. Else, the router could use vulnerabilities in your OS software (including any printer, webcam, etc) or in one of your applications or configuration. :)
[toc] | [prev] | [next] | [standalone]
| From | Marc SCHAEFER <schaefer@alphanet.ch> |
|---|---|
| Date | 2021-01-21 08:38 +0100 |
| Message-ID | <rubb1i$vbi$1@shakotay.alphanet.ch> |
| In reply to | #68 |
AnonUser <anonuser@rocksolidbbs.com.remove-32i-this> wrote: > Is there a way to check which dns server software is being used? I mean other than having full login access to whatever it runs. I would assume that if it has a Linux or BSD OS, and it has a DNS functionnality, it is dnsmasq.
[toc] | [prev] | [standalone]
Back to top | Article view | rocksolid.shared.security
csiph-web