Tag Archive for 'planet'

Kabel Deutschland breaks DNS System for it’s customers

Last week I noticed, that Kabel Deutschland, a cable provider in germany, returns for any non existing hosts “204.9.89.60″. It seems, thats it is rolled out since last fall. Even for DNSSEC enabled infrastructure it breaks it totally:

; <<>> DiG 9.3.4 <<>> +dnssec web.pixaco.se @83.169.184.161
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; ANSWER SECTION:
web.pixaco.se. 0 IN A 204.9.89.60

Beside that, this behavour breaks the whole DNS, since many mechanism rely on a negative answer. The most visible effect for the users is, that when having a typo on surfing, he will forwarded to http://suche.kabeldeutschland.de/de.kde.assist/?domain=<domainyoutypedinyourprompt>. Since 204.9.88.0/21 is located at our transatlantic friends from US, there might be some problem with leaking privacy informations. I don’t feel happy, if I had a typo in my URL and getting listed for it on any terror list or providing the newest porno links to my american friends inside the organisations with the tree capitals.

All that for getting some extra money, but racing pricedumping for connectivity, this sucks a lot.
If you are a customer and feel pissed, you can send a friendly note to them:

Kabel Deutschland Vertrieb und Service GmbH & Co. KG
Beschwerdestelle
99116 Erfurt
kundenservice@kabeldeutschland.de
Fax: 01805299925

A quick and dirty workaround for dnsmasq maybe to add “bogus-nxdomain=204.9.89.60″ to your config file. This doesn’t fix the DNSSEC problem.
The problem also pops up at dns-operations and there are traces at google too.

(old) L-root DNS Server “stolen” (for a short time)

After shutdown of the old L.ROOT-SERVERS.NET the IP address formerly associated with it, the IP continued to answere requests. More informations can be found at the ICANN Blog
UPDATE: Before bothering around, if you read the ICANN Blog, you realize that the issue was fixed very shortly. The whole problem is, that the file of the root DNS servers have to be keeped up to date. This issue should be fixed by operator of resolving nameservers (usually your ISP). A goody will be, to have this fixed by the next point release of debian, but it is NOT security critical.
Thanks Thijs for make me sensible that my article may misslead people who are not reading the referenced document.
UPDATE 2: A more technical description can also be found at Renesys Blog and a disussion how it is related to debian.

off for vacation

I’m off for vacation for just a week without any internet access (Oh my good, I will hate my inbox). This break will give me some time for my wife and my daughter before my second daughter will arrive in this world which is scheduled for mid june.
If there anything strange happen with my packages, just feel free for a 0day NMU.
Just after this week, I will attend to RIPE 56 where my latency will just a bit lower than normal.

[security] wordpress 2.5.1 which fixes CVE-2008-1930

Cause the subject, I did build a new package which can be installed on etch, lenny and of course sid. You can fetch it from http://ftp.cyconet.org/debian/archive/bpo/wordpress/2.5.1-1~bpo40+1/ or get via

deb http://ftp.cyconet.org/debian etch-backports main non-free contrib

Selfnote: Dump the wordpress user into separate domU




Too Cool for Internet Explorer