Project

General

Profile

Actions

Bug #3683

closed

pfSense Not Blocking Pre-Auth Captive Portal DNS Requests

Added by Kyle Fergusson almost 10 years ago. Updated almost 10 years ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
Captive Portal
Target version:
-
Start date:
05/29/2014
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
Affected Architecture:

Description

pfSense appears to be susceptible to DNS Tunneling attacks. I've got a neighbor who's dishTV keeps associating with my guest wifi on which I have pfSense handling with a Captive Portal. The neighbor get's an IP, then starts putting through DNS packets that get forwarded to dishaccess.tv. Because Dish has NS records, the packets travel all the way to their authoritative servers and back again. pfSense should be blocking these packets pre-auth.

Things I've tried....
Setting/Unsetting - System --> General --> DNS servers Entries
Setting/Unsetting - System --> General --> Do not use the DNS Forwarder as a DNS server for the Firewall
Setting/Unsetting - Services --> DNS Forwarder, various combos
Setting/Unsetting - Servces --> DHCP Server, various combos for DNS entries

This problem may not only be a Captive Portal issue as I think there may be root DNS packet mishandling issue. Even with an ipv4 tcp/udp block all rule on the guest wifi interface, packets still get through.

I've attached a FULL packet capture to show traffic that gets established. I even had the block all rule in place when it was captured.


Files

packet.capture.txt (12.2 KB) packet.capture.txt Kyle Fergusson, 05/29/2014 05:25 PM
Actions

Also available in: Atom PDF