Re: djbdns/dnscache poisoning weakness
Matthew Dempsky <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Feb 9, 2009 at 3:04 PM, Kevin Day <[email protected]> wrote: > When I get back into the office in the morning, I'll dig up my notes from > when I first looked at all of this. I seem to remember coming to the > decision that this wasn't exploitable for one reason or another. Have you had a chance to find these notes? (I'm just curious what you thought was different about CNAME queries; even with both SOA and negative-CNAME responses cached, an attacker could just target something like $NONCE.google.com that won't be cached anyway and poison the cache purely through glue records.)