Re: djbdns/dnscache poisoning weakness
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Mon, 9 Feb 2009, Kevin Day wrote: > > SOA should not be cached; if it is cached, one can't find out if the > > SOA > > has changed promptly, and zone transfers won't work in a timely > > manner. > > There is no reason to cache SOA records. > > > > Zone transfers don't occur through a caching name server. Dnscache > should never sit between two servers doing zone transfers. Even if > they are, the TTL on a SOA record works no differently than any other > record. If you don't want it to be cached for a long time, say so. > This isn't a problem. Admins might use caching nameservers to check SOAs. Other software might make also use of this. I can't say that there isn't any use for SOA's other than by zone transfer. All I can say is that if one does look at SOA's, one doesn't want to look at a _cached_ SOA, even if one uses a caching nameserver. > I really wish you would detail how this makes anything WEAKER. I did. I'll have to look up the difference between what we talked about off-list, which I am no longer promised to silence on, and what was posted to the list. > Dean, I have to say I'm disappointed. > > Back when news of this first leaked out back in August, you > (justifiably so) basically told me to disclose the vulnerabilities or > shut up about it. I wasn't able to discuss this then, so the talk > moved to a private series of emails between you, me and Dan Kaminsky. Yep. And apparently, I guessed nearly everything you were going to claim. I disabused your claims then, and announced that disabusal to the list. As I recall, You claimed I violated some confidence we hadn't then agreed to, and so I then agreed to keep quiet until Feb 9,2009 on your promise to share with me the vulnerabilities. I got your first document on Jan 29, 2009, and due to work on organizing FSF and LPF activities against the IETF TLS-authz document Last Call, I didn't have time to read it. But I had no idea you had nothing more. I am disappointed in you, but I should not have been surprised. It is the nature of blackhat hacking to 'social engineer' (mislead) people. Taking a cue from Kevin Mitnick, if one can't break into the source archive, its a neat hack to social engineer the changes one wants. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000