DNS vulnerability issue

vodacom3g

Vodacom Representative
Joined
Jan 14, 2005
Messages
12,065
Reaction score
2
Location
(mostly) Plattekloof, Cape Town
Anyone tested the Vodacom 3G DNS servers with the doxpara test for the DNS vulnerability issue?

If you do, please post your area and the APN you're using. Something like:

- JHB:internet - fine / not fine.
 
Cape Town, internet APN, PPDB:
Your name server, at 196.207.40.165, appears to be safe, but make sure the ports listed below aren't following an obvious pattern.Requests seen for b4aa815bcf76.toorrr.com:
196.207.40.165:13332 TXID=62043
196.207.40.165:55871 TXID=56233
196.207.40.165:25393 TXID=13213
196.207.40.165:36971 TXID=30093
196.207.40.165:22689 TXID=35972
 
Cape Town, unrestricted APN, PPDB

Your name server, at 196.207.40.167, appears to be safe, but make sure the ports listed below aren't following an obvious pattern.Requests seen for 237e35f87837.toorrr.com:
196.207.40.167:61555 TXID=12473
196.207.40.167:61397 TXID=48093
196.207.40.167:61417 TXID=10490
196.207.40.167:61457 TXID=51235
196.207.40.167:61412 TXID=11209
 
Port Shepstone; internet APN; PPDB

After clicking on the "Check my DNS" button, the info box says:
Opera: Blank
Firefox: Connection Interrupted.
Internet Explorer: Internet Explorer cannot display the webpage


:confused:
 
Benoni / Kempton Park: internet APN:

Your name server, at 84.22.100.9, appears vulnerable to DNS Cache Poisoning.
All requests came from the following source port: 53

Do not be concerned at this time. IT administrators have only recently been apprised of this issue, and should have some time to safely evaluate and deploy a fix.Requests seen for 104b3c71defd.toorrr.com:
84.22.100.9:53 TXID=17049
84.22.100.9:53 TXID=34350
84.22.100.9:53 TXID=17175
84.22.100.9:53 TXID=42249
84.22.100.9:53 TXID=5086
 
Your name server, at 196.207.40.165, appears to be safe, but make sure the ports listed below aren't following an obvious pattern.

Vleesbaai/Mosselbaai.
Thanks V3G
 
This is not a Vodacom server. Did you hardcode your DNS server setting?

Could've been, come to think of it... Honestly can't remember:o

Was playing around with Public Root DNS servers a while back. Can't recall if I ever changed the settings back to what they were...

Apparently I never did:)

/bows head in shame..

Are you by any chance using using Opera Mini?
FF
 
Last edited:
Could've been, come to think of it... Honestly can't remember:o

Was playing around with Public Root DNS servers a while back. Can't recall if I ever changed the settings back to what they were...

Apparently I never did:)

/bows head in shame..


FF
Retest & post the results after changing back to the automatically assigned DNS settings from Vodacom...
 
Somerset West, internet APN, PPDB:

Your name server, at 196.207.40.165, appears to be safe, but make sure the ports listed below aren't following an obvious pattern.Requests seen for ce721d793015.toorrr.com:
196.207.40.165:29949 TXID=25314
196.207.40.165:47066 TXID=17915
196.207.40.165:56054 TXID=45449
196.207.40.165:37637 TXID=30653
196.207.40.165:42682 TXID=520

Somerset West, internetvpn APN, PPDB:

Your name server, at 196.207.40.165, appears to be safe, but make sure the ports listed below aren't following an obvious pattern.Requests seen for 5afafdcedfaf.toorrr.com:
196.207.40.165:54982 TXID=57158
196.207.40.165:55722 TXID=52933
196.207.40.165:3275 TXID=48364
196.207.40.165:58674 TXID=16924
196.207.40.165:27406 TXID=13228
 
Randpark Ridge : internet apn

Your name server, at 196.43.38.190, appears to be safe, but make sure the ports listed below aren't following an obvious pattern.Requests seen for d5d69b7220e3.toorrr.com:
196.43.38.190:38929 TXID=51774
196.43.38.190:40709 TXID=21330
196.43.38.190:13520 TXID=22581
196.43.38.190:64809 TXID=55010
196.43.38.190:1397 TXID=63249
 
WE did apply the patch the same ay it became available but I just wanted to make 100% sure we did not miss something.

So far, so good, it seems.

PS. I guess VC should have put out a press-release stating that IS's servers were not secure for the few hours it took them to apply the patch. And that Vodacom is very concerned about IS's unsecured services ;)
 
PS. I guess VC should have put out a press-release stating that IS's servers were not secure for the few hours it took them to apply the patch. And that Vodacom is very concerned about IS's unsecured services ;)

:D
 
PS. I guess VC should have put out a press-release stating that IS's servers were not secure for the few hours it took them to apply the patch. And that Vodacom is very concerned about IS's unsecured services ;)

LOL
 
Here we go - again:D

Benoni / Kempton Park: internet APN:

Your name server, at 196.207.32.83, appears to be safe, but make sure the ports listed below aren't following an obvious pattern.Requests seen for 9789a88cde23.toorrr.com:
196.207.32.83:59649 TXID=5576
196.207.32.83:59664 TXID=21823
196.207.32.83:59698 TXID=61711
196.207.32.83:59794 TXID=57338
196.207.32.83:59633 TXID=19577
 
Kensinton internet apn:

Your name server, at 196.207.32.83, appears to be safe, but make sure the ports listed below aren't following an obvious pattern.Requests seen for 40f1e394616e.toorrr.com:
196.207.32.83:59628 TXID=50687
196.207.32.83:59634 TXID=60248
196.207.32.83:59851 TXID=9801
196.207.32.83:59822 TXID=7390
196.207.32.83:59818 TXID=28094
 
Cape Town (Parow), InternetVPN, PPDB

DoxPara DNS Check Results: (No clue what it means though)

Your name server, at 196.207.40.167, may be safe, but the NAT/Firewall in front of it appears to be interfering with its port selection policy. The difference between largest port and smallest port was only 221.

Please talk to your firewall or gateway vendor -- all are working on patches, mitigations, and workarounds.
Requests seen for 271aee723888.toorrr.com:
196.207.40.167:61534 TXID=435
196.207.40.167:61380 TXID=8671
196.207.40.167:61491 TXID=6882
196.207.40.167:61341 TXID=52739
196.207.40.167:61562 TXID=51889
 
Top
Sign up to the MyBroadband newsletter
X