Re: djbdns/dnscache poisoning weakness
Kevin Day <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Feb 16, 2009, at 4:24 PM, Matthew Dempsky wrote: > On Mon, Feb 9, 2009 at 3:04 PM, Kevin Day <[email protected]> wrote: >> When I get back into the office in the morning, I'll dig up my >> notes from >> when I first looked at all of this. I seem to remember coming to the >> decision that this wasn't exploitable for one reason or another. > > Have you had a chance to find these notes? (I'm just curious what you > thought was different about CNAME queries; even with both SOA and > negative-CNAME responses cached, an attacker could just target > something like $NONCE.google.com that won't be cached anyway and > poison the cache purely through glue records.) Sorry, I've been really sick the past few weeks and work has kinda been piling up. I remember ruling this out, but can't find any note as to why, and can't think of any reason why now either. It may just have been "someone already has a patch to fix the CNAME issue", but I honestly can't remember. I think you're right though, it is the same as the SOA issue. -- Kevin