Re: djbdns/dnscache poisoning weakness

Matthew Dempsky <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Thu, Feb 12, 2009 at 1:41 PM, Paul Jarc <[email protected]> wrote:
> Ah, right.  So that works if the attacker can detect a successful
> forgery, and send the last batch of 200 queries, all before any
> geniuine responses come in.

Correct, but don't downplay it too much.  The only capability involved
here that this attack isn't already predicated upon is being able to
send a query to dnscache and receive the response it sends.  If you
send a query for your poisoned record, it should be cached, and
dnscache will respond to it immediately, so there's no worry about it
being dropped by the query flood.

> If they can't do that, or don't care to
> bother, they have to use one query name to poison a different a
> different name.  Right?

Right, they have to poison a record that the authoritative server's
response packet will not overwrite.  E.g., if you're flooding SOA
queries for google.com, your forged response could include a bogus NS
record for l.google.com.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.