Re: djbdns/dnscache poisoning weakness

Kevin Day <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
Okay, last shot at setting the record straight. If this doesn't do it,  
I'm keeping quiet unless the email is in the form of "If you do  
[xxxx], you can poison dnscache in 1000 messages."

>
> On Tue, 10 Feb 2009, Mark Johnson wrote:
>
>> Please explain how Jeff King's patches make it possible to poison
>> dnscache in 1000 messages.
>
> That's easy. I never said "_Jeff King's_ patches make it possible to
> poison dnscache in 1000 messages." I said that about the Day/Kaminsky
> proposed changes for the same "vulnerabilities" they just quoted.

This is why I think you're either confusing me with someone else, and/ 
or are looking at the wrong patches.

1) Dan Kaminksy and I have never worked together on anything. I have  
sent a grand total of maybe 10 emails to the guy in my life. I have  
talked to YOU more than him.  I've followed his work, but we honestly  
have done nothing together. The extent of his involvement with the  
djbdns weaknesses I researched can be boiled down to: "Hey, Dan... I  
know you've been looking at DNS poisoning lately, can you look at this  
and see if I've missed anything?"  "Looks like you've found something  
interesting, Kevin. See if you can exploit it, and I'll check your  
work."

I have nothing against Dan, but it's incorrect to say that there could  
possibly be anything called "the Day/Kaminsky proposed changes." I  
don't believe there has been any overlap in anything the two of us  
have ever done.

2) The weaknesses in my paper, the suggested corrections in my paper,  
and Jeff King's patches are the same thing. Jeff was given my early  
write-up of what I'd been looking at, and came up with patches to  
correct them. As far as I'm aware, the earliest you could have  
possibly seen Jeff's patches was on February 9th, like everyone else.  
I don't know what you saw that had a weakness in the "breakable in  
1000 tries" range, but you'd made that claim long before you ever saw  
Jeff's work. Jeff's patches are directly addressing the weaknesses in  
my paper.



> "Vulnerabilities" that they never quite got around to analyzing
> mathematically, or even showing that they can be exploited in  
> reasonable
> time. I guess they decided not to try math again, after I found their
> last math analysis incorrect.
>

3) If you read the PDF I released yesterday, you'd see a pretty  
detailed example of exactly how to exploit this, as well as the data  
from 5 back-to-back test runs showing exactly how long it took. I'm  
not going to release a script-kiddie proof of concept, but everything  
you need is there to try it yourself.

4) The math for this has been done, and was actually presented at the  
Internet Society's NDSS Symposium today.

Tuesday, February 10, 2009
10:30 - 12:00
Recursive DNS Architectures and Vulnerability Implications
David Dagon, Manos Antonakakis, Xiapu Luo, Christopher P. Lee and  
Wenke Lee, Georgia Institute of Technology; Kevin Day, kevinday.com
We explore how different DNS resolver architectures affect the risk of  
DNS poisoning. To measure the threat found in existing and recent DNS  
attacks, we create a comprehensive DNS poisoning model, and  
demonstrate its sensitivity compared to previous work. We further  
catalog major architectural choices DNS implementers can make in query  
management. We note real-world instances where these choices have  
weakened the security of resolvers. Our study points to the need for  
secure DNS replacements.

I'll find out when/where the paper is viewable to those not at the  
conference. (I couldn't attend, either.)

>
> I have provided an argument, which you're just to lazy to look up.
> Though there may be some important offlist messages that need to be
> reported, yet. This is in stark contrast to Day and Kaminsky, who made
> unsubstantiated claims in July 2008, that they are just now posting
> publicly, some __8_months__ later.  I deserve the same 8 months to
> review, update or merely _RE-POST_ my arguments.
>
>

[citation needed]

I've also tried looking this up, and failed to find anything relevant.  
You emailed Dan and I with a vague understanding of the issues, but  
missing several key points. You did some math that I honestly couldn't  
figure out, and decided that the problem you think I was going to  
disclose was incorrect. That's got no bearing on what was released  
yesterday.

> Gee, I notice that this is the same sort of thing that the BIND Cartel
> says about me.  Usually before they try to silence me, while hurling
> insults and epithets.  So, now they accuse me of 'not being interested
> in civil rational discussion'. Ah, the irony of it.
>

Dean... I *tried so desperately hard* to have a rational discussion  
with you. I offered to sit on the phone with you, until one of us  
could understand the other's viewpoint. I gave you access to materials  
2 weeks before anyone else, because I honestly respected your input  
and wanted to avoid a situation like this. I was completely willing to  
pull the paper/patches if you'd come to me with any legitimate  
concerns. You didn't have time to read/email me then, but found time  
to post publicly a few hours after the deadline.

I honestly don't care what you think my motives are anymore. I'm not a  
security researcher. I'm not in this for publicity. I'm just a djbdns  
user like you, trying to keep using a package that hasn't been updated  
in around 7 years. If you can plainly identify any weakness or mistake  
in the paper or patches, not what you think you read months ago, I'm  
all ears. Otherwise, I'm done. Rather than everyone discussing DNS  
security, we're bickering over who said what and when.

-- Kevin
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.