Re: How do I know my Connection is Encrypted.
James Cameron <[email protected]> Wed, 18 Apr 2012 10:45:02 +1000
| Newsgroups | gmane.network.poptop |
|---|---|
| Organization | Netrek Vanilla Server Dictator |
| Message-ID | <[email protected]> |
On Wed, Apr 18, 2012 at 09:49:38AM +1000, Steve Phillips wrote: > On 17/04/12 8:25 PM, James Cameron wrote: > > On Mon, Apr 16, 2012 at 11:33:42PM -1000, Mike Gibbons wrote: > > > >> sudo tcpdump -i eth0 -n not proto 47 > >> > >> I saw lots of local network traffic. When I pinged yahoo.com I saw: > >> > >> 23:25:02.571512 IP 10.0.1.1.59535> 10.0.1.100.53: 19443+ A? yahoo.com. (27) > >> 23:25:02.590849 IP 10.0.1.100.53> 10.0.1.1.59535: 19443 3/0/0 A > >> 209.191.122.70, A 72.30.38.140, A 98.139.183.24 (75) > >> > >> I don't know if this means its working or not. > >> > > It means your ping of yahoo.com went direct from the client to the > > target, without going via the server. > > > > > >> Based on your analogies I'm beginning to think I need squid at the > >> server to achieve encryption back to the client. > >> > > No, you probably just need to set a default route so that all traffic > > goes via the server. > > > > > No, this is DNS, his local network (broadcast domain) has a dns server, > probably his gateway, so his client pc will always prefer that as it's > directly connected. Agreed. From the DNS query a local attacker can determine much, so I had presumed there was a leak. > The way to fix this is to set your DNS to something not on your local > network (say, on the pptp server would be a good place) and then pass > these addresses back via LCP Agreed. Mike, I suggest you look deeper into the traffic observed with tcpdump and that filter I provided. As Steve says, Wireshark can also be useful. -- James Cameron http://quozl.linux.org.au/ ------------------------------------------------------------------------------ Better than sec? Nothing is better than sec when it comes to monitoring Big Data applications. Try Boundary one-second resolution app monitoring today. Free. http://p.sf.net/sfu/Boundary-dev2dev