Re: djbdns/dnscache poisoning weakness

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Mon, 9 Feb 2009, Kevin Day wrote:

> > SOA should not be cached; if it is cached, one can't find out if the  
> > SOA
> > has changed promptly, and zone transfers won't work in a timely  
> > manner.
> > There is no reason to cache SOA records.
> >
> 
> Zone transfers don't occur through a caching name server. Dnscache  
> should never sit between two servers doing zone transfers. Even if  
> they are, the TTL on a SOA record works no differently than any other  
> record. If you don't want it to be cached for a long time, say so.  
> This isn't a problem.

Admins might use caching nameservers to check SOAs. Other software might
make also use of this.  I can't say that there isn't any use for SOA's
other than by zone transfer.  All I can say is that if one does look at
SOA's, one doesn't want to look at a _cached_ SOA, even if one uses a
caching nameserver.

> I really wish you would detail how this makes anything WEAKER.

I did. I'll have to look up the difference between what we talked about 
off-list, which I am no longer promised to silence on, and what was 
posted to the list.

> Dean, I have to say I'm disappointed.
> 
> Back when news of this first leaked out back in August, you  
> (justifiably so) basically told me to disclose the vulnerabilities or  
> shut up about it. I wasn't able to discuss this then, so the talk  
> moved to a private series of emails between you, me and Dan Kaminsky.  

Yep.  And apparently, I guessed nearly everything you were going to
claim.  I disabused your claims then, and announced that disabusal to
the list. As I recall, You claimed I violated some confidence we hadn't
then agreed to, and so I then agreed to keep quiet until Feb 9,2009 on
your promise to share with me the vulnerabilities. I got your first
document on Jan 29, 2009, and due to work on organizing FSF and LPF
activities against the IETF TLS-authz document Last Call, I didn't have
time to read it. But I had no idea you had nothing more.

I am disappointed in you, but I should not have been surprised. It is
the nature of blackhat hacking to 'social engineer' (mislead) people.  
Taking a cue from Kevin Mitnick, if one can't break into the source
archive, its a neat hack to social engineer the changes one wants.

		--Dean


-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.