OpenDNS As Quick-Fix To DNS Patch Dilemma
CWmike writes "It turns out that problems with the July 8 patch that was rolled out to fix a cache poisoning flaw discovered by researcher Dan Kaminsky are causing headaches for admins. Preston Gralla suggests a 30-second quick-fix, perhaps until everyone is patched up: Use OpenDNS, which has been patched, as your personal DNS. If you run a corporate network and need help getting OpenDNS set up, your best bet is to go to the OpenDNS FAQ page, he writes."
If you run a corporate network and need the FAQ page to help, you should not be running a corporate network.
Then your job should promptly be given to me.
Quick everyone - all of our eggs in the OpenDNS basket!
You can actually turn that off when you log in (creating an account is free).
Just log in, click the "settings" tab, and the settings you are looking for are in there.
bork bork bork!
Seriously, this solution has been posted in response to every DNS article on Slashdot this past month and has been mentioned by just about every article talking about the issue.
Does Slashdot really need to post links to Computer World that rehash was has been discussed 100 times already?
ÕÕ
Hush now, we're trying to advertise OpenDNS. Just use it and shut up like a good lemming.
No.
OpenDNS does terrible NX-overriding and other useless, annoying things (logins, etc..)
Instead, just use public, geo-distributed DNS servers which FOLLOW RFC and are patched. Here are the standard suggestions (Level7):
4.2.2.1 through 4.2.2.6.
These have good randomness and are multi-cast addresses for DNS servers all over the country. They are VERY fast in most areas.
supersloshy: "Come on, mom, I'm 32 years old, I can look at porn if I want to."
mom: "Not while you're living under my roof without paying rent!"
step-dad: "Besides, son, I hear it can help protect you against that dns cache poisoning that's been going on."
supersloshy: "Shut up! You're not my real dad!"
real dad: "Now supersloshy, you obey your step father, even if he does dress funny and try too hard."
supersloshy: "I hate you! I wish I'd never been born!"
Whole thing sounds kind of silly now, huh?
Oh, and while not naming em, let just say I have a screenshot from long ago that I took from a trace route to Google that I did, and all of the routers that my ISP owned on the way had been renamed to something like "xyz-cannot-secure-their-routers.xyz.com" and such things. Nuff said :)