Re: djbdns/dnscache poisoning weakness
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 10 Feb 2009, Matthew Dempsky wrote: > On Tue, Feb 10, 2009 at 2:27 PM, Dean Anderson <[email protected]> wrote: > > Admins might use caching nameservers to check SOAs. > > Then they get the consequences of using a caching nameserver; i.e., > the results might have been cached. > > > All I can say is that if one does look at SOA's, one doesn't want to > > look at a _cached_ SOA, even if one uses a caching nameserver. But then the admin/software has to know the nameserver. Using a recursive cache is nice becaue the recursor will find a nameserver and answer the query. > As much as I hate the idea of using BIND as an example, BIND caches > SOA records, and so I expect the majority of DNS software will have to > deal with the possibility of a caching nameserver caching SOA records. This is a good argument, and is a legitimate reason for change, but I'm not sure its a convincing argument. What are the harms of leaving it as-is? That one can keep trying an attack? Well, that's no matter: One can keep trying non-existant records, too. An attack on DNScache requires a very large number of packets, which would probably noticed as a DOS attack. I think a better solution is to adapt to make TCP queries when this is noticed, and have a configuration option to do TCP all the time. Also, does anyone know anything about an HP resolver that did only TCP? I've found some mention, but nothing definite. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000