Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 18 Feb 2009, Paul Jarc wrote: > Dean Anderson <[email protected]> wrote: > > In either case, instead of trying to find 200 ports out of 64510, > > one knows the 200 ports + plus those in use by other things. In that > > case, the task is significantly reduced. If there is just one port > > for DJBDNS plus those in use by other things, the task is easier > > still. Reducing the number of ports being used and returned affects > > the entropy of the port numbers and makes another attack possible. > > Ok, I think I see what you're saying. If I'm right, a description > like this would have been far, far clearer: > 1. An attacker floods a qmerge-patched dnscache with 200 identical > queries. > 2. dnscache forgets all previous outgoing queries, and sends just one > new outgoing query. > 3. The attacker probes the dnscache box to see what UDP ports are in > use. > 4. The attacker uses only those ports in their forged responses. > Since the attacker has reduced the number of ports to choose from > by possibly as many as 199, the odds are better of guessing the > right port. > > Is this the attack you have in mind? That's one scenario. Another scenario is they DOS attack the authority server, and cause either the single query or the single response to be lost, enabling a longer time on the attack. > I don't think this attack works any better against a qmerge-patched > dnscache. Although dnscache forgets about its previous outgoing > queries, the kernel doesn't know that it has forgotten. There's no > external evidence that would show up in the attacker's probe. > > Day and Kaminsky have been working together since Kaminsky claimed that > > DNScache was vulnerable at Blackhat last summer. > > "Working together" sounds like an overstatement, based on what Kevin > has said. Sure, going by Kevin's recent statements, you are exactly right. But Kevin's recent statements weren't very forthright; based on the emails I have from them both. You can also see that based on the very first email Kevin sent to the list in August. > Not that it matters, anyway - I'm not going to speculate > about anyone's motives. I just want to understand the technical > impact of the patch, which is independent of anyone's motives. Motives? I'm talking about Reputation. There is no way that I'm going to accept patches from blackhats. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000