Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky
Matthew Dempsky <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
I want you to describe a step-by-step algorithm that an attacker follows to trick dnscache into accepting a forged packet. This means describing what kind of query packets the attacker sends to dnscache and also what kind of forged response packets the attacker sends to dnscache. This means detailing for the query packets what the type and name in the question section should be, and for the response packets what the destination port, txid, and type and name in the question section should be. I want you to describe with sufficient detail the algorithm could be implemented unambiguously. Once you do this, we can analyze the probability of success, either theoretically or empirically. In the mean time, you're trying to apply analysis to an unspecified algorithm, and you seem thoroughly confused on how to do it. Have you ever taken an algorithms analysis or cryptography class?