Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 18 Feb 2009, Matthew Dempsky wrote: > On Wed, Feb 18, 2009 at 1:07 PM, Dean Anderson <[email protected]> wrote: > > If one has fewer ports being used by DNScache, one might be able to > > discover those ports by scanning. > > How do you suggest to scan for these ports? I hacked dnsq to wait > much longer than normal for UDP response packets and ran it on both > Linux and OpenBSD, sending queries to a non-existent host on the local > network. I then ran "nmap -sU" against each of these machines > including both the port in use by dnsq as well as some other unused > ports, and nmap listed all of them as "closed". Hmm. You might try tcpdump and see if you are getting ICMP port unreachable messages during the scan. And check your f/w config to see if you are already blocking these. > > Blocking ICMP might help, but an unprivileged process on the same > > machine can't be blocked, and can usually get a list of ports. > > This is a luxury most attackers don't have, I guess it depends on whether the attacker is attacking a cache on a multi-user machine or not. > and it's irrelevant to the discussion of Kevin Day's qmerge patch: > dnscache is equally vulnerable to a local process that can see which > UDP ports are in use whether the qmerge patch has been applied or not. I guess it depends on the query load. If there are other, ordinary queries that are repeated, there will be more ports in use without the patch than with the patch. If the attacker spaces his queries too close together, he gets multiple ports without the patchs. > > If there is just one port for DJBDNS plus those in use by other > > things, the task is easier still. Reducing the number of ports > > being used and returned affects the entropy of the port numbers and > > makes another attack possible. > > What do you do about a dnscache server that only ever receives 1 query > at a time? Do you think it's more vulnerable to forgeries than one > that constantly has 200 queries to resolve concurrently? Should > administrators add artificial load to their dnscache installations to > ensure that they always have 200 active queries? Most servers have load. Unloaded servers probably aren't much of a target for poisoning. But if you have an unloaded server for some reason, perhaps a wider question should be asked about whether the server is vulnerable to attack based on non-use. There may be many ways to fix that. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000