Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Wed, 18 Feb 2009, Paul Jarc wrote:

> Dean Anderson <[email protected]> wrote:
> > In either case, instead of trying to find 200 ports out of 64510,
> > one knows the 200 ports + plus those in use by other things. In that
> > case, the task is significantly reduced.  If there is just one port
> > for DJBDNS plus those in use by other things, the task is easier
> > still.  Reducing the number of ports being used and returned affects
> > the entropy of the port numbers and makes another attack possible.
> 
> Ok, I think I see what you're saying.  If I'm right, a description
> like this would have been far, far clearer:
> 1. An attacker floods a qmerge-patched dnscache with 200 identical
>    queries.
> 2. dnscache forgets all previous outgoing queries, and sends just one
>    new outgoing query.
> 3. The attacker probes the dnscache box to see what UDP ports are in
>    use.
> 4. The attacker uses only those ports in their forged responses.
>    Since the attacker has reduced the number of ports to choose from
>    by possibly as many as 199, the odds are better of guessing the
>    right port.
> 
> Is this the attack you have in mind?

That's one scenario. 

Another scenario is they DOS attack the authority server, and cause 
either the single query or the single response to be lost, enabling a 
longer time on the attack.

> I don't think this attack works any better against a qmerge-patched
> dnscache.  Although dnscache forgets about its previous outgoing
> queries, the kernel doesn't know that it has forgotten.  There's no
> external evidence that would show up in the attacker's probe.




> > Day and Kaminsky have been working together since Kaminsky claimed that
> > DNScache was vulnerable at Blackhat last summer.
> 
> "Working together" sounds like an overstatement, based on what Kevin
> has said.  

Sure, going by Kevin's recent statements, you are exactly right. But
Kevin's recent statements weren't very forthright; based on the emails I
have from them both. You can also see that based on the very first email
Kevin sent to the list in August. 

> Not that it matters, anyway - I'm not going to speculate
> about anyone's motives.  I just want to understand the technical
> impact of the patch, which is independent of anyone's motives.

Motives?  I'm talking about Reputation.  There is no way that I'm going 
to accept patches from blackhats. 

		--Dean

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.