<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Exploit in the wild for the Kaminsky DNS vulnerability</title>
	<atom:link href="http://www.spylogic.net/2008/07/exploit-in-the-wild-for-the-kaminsky-dns-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spylogic.net/2008/07/exploit-in-the-wild-for-the-kaminsky-dns-vulnerability/</link>
	<description></description>
	<lastBuildDate>Sun, 18 Sep 2011 21:48:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: CG</title>
		<link>http://www.spylogic.net/2008/07/exploit-in-the-wild-for-the-kaminsky-dns-vulnerability/comment-page-1/#comment-75</link>
		<dc:creator>CG</dc:creator>
		<pubDate>Thu, 24 Jul 2008 00:22:17 +0000</pubDate>
		<guid isPermaLink="false">#comment-75</guid>
		<description>Don&#039;t get me wrong I&#039;m not saying its not dangerous, its just frustrating that people immediately lump a metasploit module --especially in this case because its only an aux module with script kiddie mass pwnage.&lt;br /&gt;
&lt;br /&gt;
with the number of  &quot;why cant i exploit my XP SP2+ box with DCOM&quot; questions I see and take, I dont think we have to be too worried about the lowest common denominator on this one.</description>
		<content:encoded><![CDATA[<p>Don&#8217;t get me wrong I&#8217;m not saying its not dangerous, its just frustrating that people immediately lump a metasploit module &#8211;especially in this case because its only an aux module with script kiddie mass pwnage.</p>
<p>with the number of  &quot;why cant i exploit my XP SP2+ box with DCOM&quot; questions I see and take, I dont think we have to be too worried about the lowest common denominator on this one.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://www.spylogic.net/2008/07/exploit-in-the-wild-for-the-kaminsky-dns-vulnerability/comment-page-1/#comment-74</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Wed, 23 Jul 2008 23:35:20 +0000</pubDate>
		<guid isPermaLink="false">#comment-74</guid>
		<description>Point taken.  I saw on Wired: Threat Level that HD said the following about his module:&lt;br /&gt;
&lt;br /&gt;
&quot;Moore says the code currently has a limitation:&lt;br /&gt;
&lt;br /&gt;
This exploit can&#039;t be used to overwrite an existing cache entry, so attackers will have a hard time spoofing common host names on busy DNS servers. The module added to Metasploit will display the expiration date for any pre-cached entries and automatically wait for that amount of time for completing the attack.&quot;&lt;br /&gt;
&lt;br /&gt;
Correct.  This might be a bit more technical then what a basic script kiddie could be capable of.  Seems that you would just have to wait for the cached entries to expire...?&lt;br /&gt;
&lt;br /&gt;
Has anyone tested this in a lab yet?</description>
		<content:encoded><![CDATA[<p>Point taken.  I saw on Wired: Threat Level that HD said the following about his module:</p>
<p>&quot;Moore says the code currently has a limitation:</p>
<p>This exploit can&#8217;t be used to overwrite an existing cache entry, so attackers will have a hard time spoofing common host names on busy DNS servers. The module added to Metasploit will display the expiration date for any pre-cached entries and automatically wait for that amount of time for completing the attack.&quot;</p>
<p>Correct.  This might be a bit more technical then what a basic script kiddie could be capable of.  Seems that you would just have to wait for the cached entries to expire&#8230;?</p>
<p>Has anyone tested this in a lab yet?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CG</title>
		<link>http://www.spylogic.net/2008/07/exploit-in-the-wild-for-the-kaminsky-dns-vulnerability/comment-page-1/#comment-73</link>
		<dc:creator>CG</dc:creator>
		<pubDate>Wed, 23 Jul 2008 22:56:17 +0000</pubDate>
		<guid isPermaLink="false">#comment-73</guid>
		<description>really?  the average script kiddie knucklehead is about to download that module and actually get anywhere with it?&lt;br /&gt;
&lt;br /&gt;
doubtful.</description>
		<content:encoded><![CDATA[<p>really?  the average script kiddie knucklehead is about to download that module and actually get anywhere with it?</p>
<p>doubtful.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

