Re: djbdns/dnscache poisoning weakness
Matthew Dempsky <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Feb 12, 2009 at 1:41 PM, Paul Jarc <[email protected]> wrote: > Ah, right. So that works if the attacker can detect a successful > forgery, and send the last batch of 200 queries, all before any > geniuine responses come in. Correct, but don't downplay it too much. The only capability involved here that this attack isn't already predicated upon is being able to send a query to dnscache and receive the response it sends. If you send a query for your poisoned record, it should be cached, and dnscache will respond to it immediately, so there's no worry about it being dropped by the query flood. > If they can't do that, or don't care to > bother, they have to use one query name to poison a different a > different name. Right? Right, they have to poison a record that the authoritative server's response packet will not overwrite. E.g., if you're flooding SOA queries for google.com, your forged response could include a bogus NS record for l.google.com.