<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Test dnsmasq available, fix for potential cache poisoning vulnerability</title>
	<atom:link href="http://blog.pfsense.org/?feed=rss2&#038;p=210" rel="self" type="application/rss+xml" />
	<link>http://blog.pfsense.org/?p=210</link>
	<description>News, reviews and more related to the pfSense firewall project</description>
	<lastBuildDate>Sat, 25 May 2013 21:29:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: pfSense Digest &#187; Blog Archive &#187; DNS vulnerability details now publicly available</title>
		<link>http://blog.pfsense.org/?p=210&#038;cpage=1#comment-1637</link>
		<dc:creator>pfSense Digest &#187; Blog Archive &#187; DNS vulnerability details now publicly available</dc:creator>
		<pubDate>Wed, 23 Jul 2008 02:23:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pfsense.org/?p=210#comment-1637</guid>
		<description><![CDATA[[...] own DNS server and haven&#8217;t patched yet - now would be the time to do so. The details of the previously mentioned vulnerability were inadvertently made publicly available earlier [...]]]></description>
		<content:encoded><![CDATA[<p>[...] own DNS server and haven&#8217;t patched yet &#8211; now would be the time to do so. The details of the previously mentioned vulnerability were inadvertently made publicly available earlier [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ronpfs</title>
		<link>http://blog.pfsense.org/?p=210&#038;cpage=1#comment-1576</link>
		<dc:creator>Ronpfs</dc:creator>
		<pubDate>Sat, 12 Jul 2008 16:44:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pfsense.org/?p=210#comment-1576</guid>
		<description><![CDATA[Chris said  &quot;don’t access the webGUI by hostname if your client is using that system for its DNS.&quot;

That is exactly what I meant  ;o)  Not a big thing cause once your client can&#039;t resolve the hostname a few synaps fire and you switch to IP ;o)

Working ok here too]]></description>
		<content:encoded><![CDATA[<p>Chris said  &#8220;don’t access the webGUI by hostname if your client is using that system for its DNS.&#8221;</p>
<p>That is exactly what I meant  ;o)  Not a big thing cause once your client can&#8217;t resolve the hostname a few synaps fire and you switch to IP ;o)</p>
<p>Working ok here too</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Uthe</title>
		<link>http://blog.pfsense.org/?p=210&#038;cpage=1#comment-1575</link>
		<dc:creator>Chris Uthe</dc:creator>
		<pubDate>Sat, 12 Jul 2008 00:12:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pfsense.org/?p=210#comment-1575</guid>
		<description><![CDATA[Working great on 1.2 stable here!]]></description>
		<content:encoded><![CDATA[<p>Working great on 1.2 stable here!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Buechler</title>
		<link>http://blog.pfsense.org/?p=210&#038;cpage=1#comment-1574</link>
		<dc:creator>Chris Buechler</dc:creator>
		<pubDate>Sat, 12 Jul 2008 00:00:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pfsense.org/?p=210#comment-1574</guid>
		<description><![CDATA[Fetching the updated file isn&#039;t relevant to whether or not dnsmasq is running, since the local system uses /etc/resolv.conf. 

I think ronpfs means don&#039;t access the webGUI by hostname if your client is using that system for its DNS. That shouldn&#039;t matter either as the DNS cache on your client system should be more than long enough to accommodate doing this, but it&#039;s not bad advice.]]></description>
		<content:encoded><![CDATA[<p>Fetching the updated file isn&#8217;t relevant to whether or not dnsmasq is running, since the local system uses /etc/resolv.conf. </p>
<p>I think ronpfs means don&#8217;t access the webGUI by hostname if your client is using that system for its DNS. That shouldn&#8217;t matter either as the DNS cache on your client system should be more than long enough to accommodate doing this, but it&#8217;s not bad advice.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://blog.pfsense.org/?p=210&#038;cpage=1#comment-1573</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Fri, 11 Jul 2008 23:06:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pfsense.org/?p=210#comment-1573</guid>
		<description><![CDATA[For DNS Resloving in the shell i believe it uses /etc/resolv.conf and asks the DNS servers directly. I killed dnsmasq and was able to ping domain names from the shell all day long.  I also did the update with the domain name and it worked fine. 

Using the ip can&#039;t hurt :)]]></description>
		<content:encoded><![CDATA[<p>For DNS Resloving in the shell i believe it uses /etc/resolv.conf and asks the DNS servers directly. I killed dnsmasq and was able to ping domain names from the shell all day long.  I also did the update with the domain name and it worked fine. </p>
<p>Using the ip can&#8217;t hurt <img src='http://blog.pfsense.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ronpfs</title>
		<link>http://blog.pfsense.org/?p=210&#038;cpage=1#comment-1572</link>
		<dc:creator>Ronpfs</dc:creator>
		<pubDate>Fri, 11 Jul 2008 22:09:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pfsense.org/?p=210#comment-1572</guid>
		<description><![CDATA[Remember to use the ip and not the domain name for the WebGUI / Diagnostics -&gt; Command, cause you gonna kill the DNS server during the procedure.]]></description>
		<content:encoded><![CDATA[<p>Remember to use the ip and not the domain name for the WebGUI / Diagnostics -&gt; Command, cause you gonna kill the DNS server during the procedure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Buechler</title>
		<link>http://blog.pfsense.org/?p=210&#038;cpage=1#comment-1571</link>
		<dc:creator>Chris Buechler</dc:creator>
		<pubDate>Fri, 11 Jul 2008 19:51:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pfsense.org/?p=210#comment-1571</guid>
		<description><![CDATA[For embedded, you first need to run: 

/etc/rc.conf_mount_rw

and when done: 

/etc/rc.conf_mount_ro]]></description>
		<content:encoded><![CDATA[<p>For embedded, you first need to run: </p>
<p>/etc/rc.conf_mount_rw</p>
<p>and when done: </p>
<p>/etc/rc.conf_mount_ro</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://blog.pfsense.org/?p=210&#038;cpage=1#comment-1570</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Fri, 11 Jul 2008 19:26:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pfsense.org/?p=210#comment-1570</guid>
		<description><![CDATA[Commands do not work via SSH and Console on 1.2 embedded

PFbox:~#  killall dnsmasq
PFbox:~#  mv /usr/local/sbin/dnsmasq /root/
mv: rename /usr/local/sbin/dnsmasq to /root/dnsmasq: Read-only file system



Confirmed working via WebGUI Command 1.2 embedded

Jul 11 15:16:33 dnsmasq[4339]: started, version 2.43rc3 cachesize 150 
Jul 11 15:16:33 dnsmasq[4339]: compile time options: IPv6 GNU-getopt BSD-bridge ISC-leasefile no-DBus no-I18N TFTP 
Jul 11 15:16:33 dnsmasq[4339]: reading /etc/resolv.conf 
Jul 11 15:16:33 dnsmasq[4339]: using nameserver x.x.x.x#53 
Jul 11 15:16:33 dnsmasq[4339]: using nameserver x.x.x.x#53 
Jul 11 15:16:33 dnsmasq[4339]: read /etc/hosts - 2 addresses]]></description>
		<content:encoded><![CDATA[<p>Commands do not work via SSH and Console on 1.2 embedded</p>
<p>PFbox:~#  killall dnsmasq<br />
PFbox:~#  mv /usr/local/sbin/dnsmasq /root/<br />
mv: rename /usr/local/sbin/dnsmasq to /root/dnsmasq: Read-only file system</p>
<p>Confirmed working via WebGUI Command 1.2 embedded</p>
<p>Jul 11 15:16:33 dnsmasq[4339]: started, version 2.43rc3 cachesize 150<br />
Jul 11 15:16:33 dnsmasq[4339]: compile time options: IPv6 GNU-getopt BSD-bridge ISC-leasefile no-DBus no-I18N TFTP<br />
Jul 11 15:16:33 dnsmasq[4339]: reading /etc/resolv.conf<br />
Jul 11 15:16:33 dnsmasq[4339]: using nameserver x.x.x.x#53<br />
Jul 11 15:16:33 dnsmasq[4339]: using nameserver x.x.x.x#53<br />
Jul 11 15:16:33 dnsmasq[4339]: read /etc/hosts &#8211; 2 addresses</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Buechler</title>
		<link>http://blog.pfsense.org/?p=210&#038;cpage=1#comment-1569</link>
		<dc:creator>Chris Buechler</dc:creator>
		<pubDate>Fri, 11 Jul 2008 18:24:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pfsense.org/?p=210#comment-1569</guid>
		<description><![CDATA[Thanks for the reports!  

A.D.:  Read the post.  &quot;This is for 1.2-release systems only, those using 1.2.1 or 1.3 snapshots can update by installing a new full update from the snapshot server.&quot;]]></description>
		<content:encoded><![CDATA[<p>Thanks for the reports!  </p>
<p>A.D.:  Read the post.  &#8220;This is for 1.2-release systems only, those using 1.2.1 or 1.3 snapshots can update by installing a new full update from the snapshot server.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathon</title>
		<link>http://blog.pfsense.org/?p=210&#038;cpage=1#comment-1568</link>
		<dc:creator>Jonathon</dc:creator>
		<pubDate>Fri, 11 Jul 2008 18:09:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.pfsense.org/?p=210#comment-1568</guid>
		<description><![CDATA[Not much of unix guy/admin, but on my home setup it seems to be working fine, even after rebooting the machine.

Thanks!]]></description>
		<content:encoded><![CDATA[<p>Not much of unix guy/admin, but on my home setup it seems to be working fine, even after rebooting the machine.</p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
