<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Apple&#8217;s Patched OpenSSH doing SRV lookups?</title>
	<atom:link href="http://www.sherman.ca/archives/2005/06/23/apples-patched-openssh-doing-srv-lookups/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sherman.ca/archives/2005/06/23/apples-patched-openssh-doing-srv-lookups/</link>
	<description>Mostly random thoughts on software, gear and the great outdoors.</description>
	<lastBuildDate>Tue, 27 Sep 2011 13:33:05 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Jon Rail</title>
		<link>http://www.sherman.ca/archives/2005/06/23/apples-patched-openssh-doing-srv-lookups/comment-page-1/#comment-283</link>
		<dc:creator>Jon Rail</dc:creator>
		<pubDate>Fri, 09 Dec 2005 16:01:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.sherman.ca/2005/06/23/apples-patched-openssh-doing-srv-lookups/#comment-283</guid>
		<description>&lt;p&gt;NB in my last comment several underscores have been removed from my command line examples (the comments system interpreted them as formating instructions).&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>NB in my last comment several underscores have been removed from my command line examples (the comments system interpreted them as formating instructions).</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Rail</title>
		<link>http://www.sherman.ca/archives/2005/06/23/apples-patched-openssh-doing-srv-lookups/comment-page-1/#comment-282</link>
		<dc:creator>Jon Rail</dc:creator>
		<pubDate>Fri, 09 Dec 2005 15:59:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.sherman.ca/2005/06/23/apples-patched-openssh-doing-srv-lookups/#comment-282</guid>
		<description>&lt;p&gt;I&#039;ve just been researching the same thing, and it seems that it&#039;s the mDNS service which I think is the actual implementation of Bonjour (aka Rendezvous).&lt;/p&gt;

&lt;p&gt;man mDNS shows examples of advertising services using the syntax:&lt;/p&gt;

&lt;p&gt;mDNS -R &quot;My Test&quot; _http._tcp . 80 (and some other stuff)&lt;/p&gt;

&lt;p&gt;And to search for a resource:&lt;/p&gt;

&lt;p&gt;mDNS -B _http._tcp&lt;/p&gt;

&lt;p&gt;I&#039;ve ran a packet capture on an ibook as it bound to Active Directory (just to make sure it was doing it sensibly before we let it near the live systems) and noticed a lot of these DNS requests milliseconds after it bound.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I&#8217;ve just been researching the same thing, and it seems that it&#8217;s the mDNS service which I think is the actual implementation of Bonjour (aka Rendezvous).</p>

<p>man mDNS shows examples of advertising services using the syntax:</p>

<p>mDNS -R &#8220;My Test&#8221; _http._tcp . 80 (and some other stuff)</p>

<p>And to search for a resource:</p>

<p>mDNS -B _http._tcp</p>

<p>I&#8217;ve ran a packet capture on an ibook as it bound to Active Directory (just to make sure it was doing it sensibly before we let it near the live systems) and noticed a lot of these DNS requests milliseconds after it bound.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: DouglasDD</title>
		<link>http://www.sherman.ca/archives/2005/06/23/apples-patched-openssh-doing-srv-lookups/comment-page-1/#comment-281</link>
		<dc:creator>DouglasDD</dc:creator>
		<pubDate>Thu, 01 Sep 2005 02:05:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.sherman.ca/2005/06/23/apples-patched-openssh-doing-srv-lookups/#comment-281</guid>
		<description>&lt;p&gt;The DNS behavior that you describe is about to get me banned / disconnected by my ISP, who say that my box is abusing their DNS to the tune of dozens of queries per second!&lt;/p&gt;

&lt;p&gt;At the time the notification was generated my box was running 10.4.2.
I&#039;ve just now updated to Security Update 2005-007 (v1.1).&lt;/p&gt;

&lt;p&gt;Since Rogers.com&#039;s tech support is so useless for non-windows, and the &quot;abuse&quot; team doesn&#039;t return emails, I guess I won&#039;t find out if the latest update fixed the issue or not until after I&#039;m banned :-P&lt;/p&gt;

&lt;p&gt;I&#039;m not yet clear whether the offending software is ssh (or client app) or sshd (the server app).&lt;/p&gt;

&lt;p&gt;Their auto-generated nasty-gram included the following log snippet:&lt;/p&gt;

&lt;p&gt;Date Time, Src, Query, Query type
 2005-08-24 10:03:02.87574, 24.157.68.55, _telnet._tcp.quickbeam.rogers.com., Internet Unknow
 2005-08-24 10:03:02.89364, 24.157.68.55, quickbeam.slnt.phub.net.cable.rogers.com., Internet Addr ?
 2005-08-24 10:03:02.91165, 24.157.68.55, quickbeam.slnt.phub.net.cable.rogers.com., Internet Addr ?
 2005-08-24 10:03:02.92965, 24.157.68.55, quickbeam.phub.net.cable.rogers.com., Internet Addr ?
 2005-08-24 10:03:02.94782, 24.157.68.55, quickbeam.phub.net.cable.rogers.com., Internet Addr ?&lt;/p&gt;

&lt;p&gt;Date Time,Dst,Query,Response
 2005-08-24 10:03:2.87637,24.157.68.55,Error:,3(Name Error)
 2005-08-24 10:03:2.89392,24.157.68.55,Error:,3(Name Error)
 2005-08-24 10:03:2.91205,24.157.68.55,Error:,3(Name Error)
 2005-08-24 10:03:2.93289,24.157.68.55,Error:,3(Name Error)
 2005-08-24 10:03:2.94814,24.157.68.55,Error:,3(Name Error)&lt;/p&gt;

&lt;p&gt;All the best,
./ddd&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>The DNS behavior that you describe is about to get me banned / disconnected by my ISP, who say that my box is abusing their DNS to the tune of dozens of queries per second!</p>

<p>At the time the notification was generated my box was running 10.4.2.
I&#8217;ve just now updated to Security Update 2005-007 (v1.1).</p>

<p>Since Rogers.com&#8217;s tech support is so useless for non-windows, and the &#8220;abuse&#8221; team doesn&#8217;t return emails, I guess I won&#8217;t find out if the latest update fixed the issue or not until after I&#8217;m banned <img src='http://www.sherman.ca/wp-includes/images/smilies/icon_razz.gif' alt=':-P' class='wp-smiley' /> </p>

<p>I&#8217;m not yet clear whether the offending software is ssh (or client app) or sshd (the server app).</p>

<p>Their auto-generated nasty-gram included the following log snippet:</p>

<p>Date Time, Src, Query, Query type
 2005-08-24 10:03:02.87574, 24.157.68.55, _telnet._tcp.quickbeam.rogers.com., Internet Unknow
 2005-08-24 10:03:02.89364, 24.157.68.55, quickbeam.slnt.phub.net.cable.rogers.com., Internet Addr ?
 2005-08-24 10:03:02.91165, 24.157.68.55, quickbeam.slnt.phub.net.cable.rogers.com., Internet Addr ?
 2005-08-24 10:03:02.92965, 24.157.68.55, quickbeam.phub.net.cable.rogers.com., Internet Addr ?
 2005-08-24 10:03:02.94782, 24.157.68.55, quickbeam.phub.net.cable.rogers.com., Internet Addr ?</p>

<p>Date Time,Dst,Query,Response
 2005-08-24 10:03:2.87637,24.157.68.55,Error:,3(Name Error)
 2005-08-24 10:03:2.89392,24.157.68.55,Error:,3(Name Error)
 2005-08-24 10:03:2.91205,24.157.68.55,Error:,3(Name Error)
 2005-08-24 10:03:2.93289,24.157.68.55,Error:,3(Name Error)
 2005-08-24 10:03:2.94814,24.157.68.55,Error:,3(Name Error)</p>

<p>All the best,
./ddd</p>]]></content:encoded>
	</item>
	<item>
		<title>By: theconsultant.net  &#38;#187; Blog Archive   &#38;#187; Tiger: OpenSSH and SRV resolution</title>
		<link>http://www.sherman.ca/archives/2005/06/23/apples-patched-openssh-doing-srv-lookups/comment-page-1/#comment-279</link>
		<dc:creator>theconsultant.net  &#38;#187; Blog Archive   &#38;#187; Tiger: OpenSSH and SRV resolution</dc:creator>
		<pubDate>Sun, 26 Jun 2005 07:16:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.sherman.ca/2005/06/23/apples-patched-openssh-doing-srv-lookups/#comment-279</guid>
		<description>&lt;p&gt;[...] irmware for Pioneer DVD drives                                            Tiger: OpenSSH and SRV resolution                                   Adam asked me to look if my OpenSSH install also does SRV loo [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] irmware for Pioneer DVD drives                                            Tiger: OpenSSH and SRV resolution                                   Adam asked me to look if my OpenSSH install also does SRV loo [...]</p>]]></content:encoded>
	</item>
</channel>
</rss>

