Re: djbdns/dnscache poisoning weakness
Mark Johnson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Feb 9, 2009 at 8:25 PM, Dean Anderson <[email protected]> wrote: > I recommend ignoring these patches and avoiding any server that uses > these patches. > > I have discovered that Kaminsky was searching for open recursors roughly > during the time of the first open recursor attack reported in October > 2005. Kaminsky reported finding about 500,000 open recursors at > Schmoocon in January 2006. > > When the 'DNS cache scare' started last summer, Kaminsky tried to get > people to convert to David Ulevitch's OpenDNS service. The scare also > prompted efforts to promote DNSSEC. These are "scare" scams, not > legitimate threats for which people should change DNS software. > > Previous analysis of the Kevin Day/Dan Kaminsky proposed changes to > DNSCACHE revealed that they would ADD EXTREME WEAKNESS not fix weakness, > making it possible to poison a cache in about 1000 messages. I have not > yet analyzed the BIND changes, and do not know if they suffer the same > weaknesses as the DNSCACHE changes. Pot. Kettle. Black. You're engaging in the same kind of scare tactics that you accuse Kevin of.