Re: djbdns/dnscache poisoning weakness

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Tue, 10 Feb 2009, Matthew Dempsky wrote:

> On Tue, Feb 10, 2009 at 2:27 PM, Dean Anderson <[email protected]> wrote:
> > Admins might use caching nameservers to check SOAs.
> 
> Then they get the consequences of using a caching nameserver; i.e.,
> the results might have been cached.
> 
> > All I can say is that if one does look at SOA's, one doesn't want to
> > look at a _cached_ SOA, even if one uses a caching nameserver.

But then the admin/software has to know the nameserver.  Using a
recursive cache is nice becaue the recursor will find a nameserver and 
answer the query.

> As much as I hate the idea of using BIND as an example, BIND caches
> SOA records, and so I expect the majority of DNS software will have to
> deal with the possibility of a caching nameserver caching SOA records.

This is a good argument, and is a legitimate reason for change, but I'm
not sure its a convincing argument.

What are the harms of leaving it as-is?  That one can keep trying an
attack?  Well, that's no matter: One can keep trying non-existant
records, too.

An attack on DNScache requires a very large number of packets, which
would probably noticed as a DOS attack.  I think a better solution is to
adapt to make TCP queries when this is noticed, and have a configuration
option to do TCP all the time.

Also, does anyone know anything about an HP resolver that did only TCP?  
I've found some mention, but nothing definite.

		--Dean


-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.