{"id":429,"date":"2014-03-19T02:54:21","date_gmt":"2014-03-19T01:54:21","guid":{"rendered":"http:\/\/abundo.se\/?p=429"},"modified":"2020-08-12T02:26:07","modified_gmt":"2020-08-12T00:26:07","slug":"kan-jag-anvanda-en-oppen-dns-resolver","status":"publish","type":"post","link":"https:\/\/abundo.se\/en\/2014\/03\/19\/kan-jag-anvanda-en-oppen-dns-resolver\/","title":{"rendered":"Kan jag anv\u00e4nda en \u00f6ppen DNS resolver?"},"content":{"rendered":"<p>Jag f\u00e5r ofta fr\u00e5gan om det g\u00e5r bra att anv\u00e4nda en \u00f6ppen rekursiv resolver, exempelvis Googles 8.8.8.8 eller de som eran Internetleverant\u00f6r erbjuder.<\/p>\n\n\n\n<p>Ska ni ha full s\u00e4kerhet i eran DNS \/ DNSSEC implementation s\u00e5 \u00e4r svaret <strong>NEJ<\/strong>.<\/p>\n\n\n\n<!--more-->\n\n\n\n<p>Kom ih\u00e5g att<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Kommunikation mellan en stub resolver (era vanliga datorer\/klienter) och en rekursiv resolver g\u00e5r helt i klartext.<\/li><li>Det \u00e4r den rekursiva resolverns jobb att verifiera DNSSEC signaturer och om de inte st\u00e4mmer f\u00e5r klienten inget svar.<\/li><li>Klienter k\u00e4nner inte till DNSSEC \u00f6verhuvudtaget, de ser bara svar eller felkoder (SERVFAIL).<\/li><\/ul>\n\n\n\n<p>Om en extern resolver anv\u00e4nds<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Kommer ni inte ha full kontroll p\u00e5 v\u00e4gen mellan era klienter och den externa resolvern<\/li><li>Det finns m\u00e5nga s\u00e4tt att p\u00e5verka DNS svaren p\u00e5 v\u00e4gen d\u00e4remellan,&nbsp;via spoofing, \u00e4ndring i globala routingen mm.<\/li><\/ul>\n\n\n\n<p>Detta har nyligen h\u00e4nt s\u00e5 det \u00e4r inte bara teori.<\/p>\n\n\n\n<p>Googles externa resolver p\u00e5 8.8.8.8 har redan blivit attackerad genom att \u00e4ndra i den globala routingtabellen. Detta finns beskrivet p\u00e5 bla <a href=\"http:\/\/thehackernews.com\/2014\/03\/google-public-dns-server-traffic.html\" target=\"_blank\" rel=\"noreferrer noopener\">http:\/\/thehackernews.com\/2014\/03\/google-public-dns-server-traffic.html<\/a><\/p>\n\n\n\n<p>Alla fr\u00e5gor till 8.8.8.8 skickades under 22 minuter till icke-Google servrar i Venezuela och Brasilien och vilka typer av svar de returnerade \u00e4r inte k\u00e4nt. Typiskt kan felaktiga IP adresser\/servrar ha returnerats f\u00f6r popul\u00e4ra hemsidor s\u00e5som Facebook, Google och Yahoo. Dessa servrar kan sedan gjort en &#8221;<a href=\"https:\/\/en.wikipedia.org\/wiki\/Man-in-the-middle_attack\" target=\"_blank\" rel=\"noreferrer noopener\">Man In The Middle<\/a>&#8221; attack och f\u00e5ngat upp anv\u00e4ndarnamn och l\u00f6senord utan att n\u00e5gon m\u00e4rkt det.<\/p>\n\n\n\n<p>S\u00e5, att anv\u00e4nda en extern resolver kan inte rekommenderas, ni beh\u00f6ver lokala s\u00e5dana som sk\u00f6ter DNSSEC validering och d\u00e4r svaret mellan resolvern och era klienter inte kan p\u00e5verkas.<\/p>","protected":false},"excerpt":{"rendered":"<p>Jag f\u00e5r ofta fr\u00e5gan om det g\u00e5r bra att anv\u00e4nda en \u00f6ppen rekursiv resolver, exempelvis Googles 8.8.8.8 eller de som eran Internetleverant\u00f6r erbjuder. Ska ni ha full s\u00e4kerhet i eran DNS \/ DNSSEC implementation s\u00e5 \u00e4r svaret NEJ.<\/p>","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-429","post","type-post","status-publish","format-standard","hentry","category-nyheter"],"_links":{"self":[{"href":"https:\/\/abundo.se\/en\/wp-json\/wp\/v2\/posts\/429","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/abundo.se\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/abundo.se\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/abundo.se\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/abundo.se\/en\/wp-json\/wp\/v2\/comments?post=429"}],"version-history":[{"count":6,"href":"https:\/\/abundo.se\/en\/wp-json\/wp\/v2\/posts\/429\/revisions"}],"predecessor-version":[{"id":1039,"href":"https:\/\/abundo.se\/en\/wp-json\/wp\/v2\/posts\/429\/revisions\/1039"}],"wp:attachment":[{"href":"https:\/\/abundo.se\/en\/wp-json\/wp\/v2\/media?parent=429"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/abundo.se\/en\/wp-json\/wp\/v2\/categories?post=429"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/abundo.se\/en\/wp-json\/wp\/v2\/tags?post=429"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}