Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Wed, 18 Feb 2009, Matthew Dempsky wrote:

> On Wed, Feb 18, 2009 at 1:07 PM, Dean Anderson <[email protected]> wrote:
> > If one has fewer ports being used by DNScache, one might be able to
> > discover those ports by scanning.
> 
> How do you suggest to scan for these ports?  I hacked dnsq to wait
> much longer than normal for UDP response packets and ran it on both
> Linux and OpenBSD, sending queries to a non-existent host on the local
> network.  I then ran "nmap -sU" against each of these machines
> including both the port in use by dnsq as well as some other unused
> ports, and nmap listed all of them as "closed".

Hmm. You might try tcpdump and see if you are getting ICMP port
unreachable messages during the scan. And check your f/w config to see
if you are already blocking these.

> > Blocking ICMP might help, but an unprivileged process on the same
> > machine can't be blocked, and can usually get a list of ports.
> 
> This is a luxury most attackers don't have, 

I guess it depends on whether the attacker is attacking a cache on a
multi-user machine or not.

> and it's irrelevant to the discussion of Kevin Day's qmerge patch:
> dnscache is equally vulnerable to a local process that can see which
> UDP ports are in use whether the qmerge patch has been applied or not.

I guess it depends on the query load.  If there are other, ordinary
queries that are repeated, there will be more ports in use without the
patch than with the patch.  If the attacker spaces his queries too close
together, he gets multiple ports without the patchs.

> > If there is just one port for DJBDNS plus those in use by other
> > things, the task is easier still.  Reducing the number of ports
> > being used and returned affects the entropy of the port numbers and
> > makes another attack possible.
> 
> What do you do about a dnscache server that only ever receives 1 query
> at a time?  Do you think it's more vulnerable to forgeries than one
> that constantly has 200 queries to resolve concurrently?  Should
> administrators add artificial load to their dnscache installations to
> ensure that they always have 200 active queries?

Most servers have load. Unloaded servers probably aren't much of a
target for poisoning.  But if you have an unloaded server for some
reason, perhaps a wider question should be asked about whether the
server is vulnerable to attack based on non-use. There may be many ways
to fix that.

		--Dean

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.