Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky

[email protected] (Paul Jarc)
Newsgroups gmane.network.djbdns
Organization What did you have in mind? A short, blunt, human pyramid?
Message-ID <[email protected]>
Dean Anderson <[email protected]> wrote:
> On Fri, 27 Feb 2009, Paul Jarc wrote:
>> Dean Anderson <[email protected]> wrote:
>>> The randombind() function tries 10 times to allocate a port, and if that
>>> fails, the port given by the kernel is used. So the port bound by
>>> randombind() is not a strong random number.  This is a side-effect of
>>> the Kaminksy/Day/King patch
>> 
>> It sounds like you're saying Jeff's patches modify the randombind()
>> function to introduce this fallback, but that's not true.  The
>> fallback is already in unpatched dnscache.
>
> I didn't say that.

Maybe I should have stressed "it sounds like" more strongly.  What I
was trying to say was: I'm not clear on what you're claiming, but
here's a response to what I think you might be claiming; if I've
mistinterpreted, then we can try again.

So you'e not claiming that the fallback to a kernel-selected port is
introduced by the qmerge patch; good.  Then what are you claiming?
What does "this" refer to in your original statement above - "this is
a side-effect..."?

I think (please correct me if I'm wrong) you're claiming that an
attacker can cause a qmerge-patched dnscache to reduce its number of
open ports for outgoing queries.  This is not true.  With or without
qmerge, dnscache doesn't bother to close the UDP socket for an
outgoing query until it's ready to send a new one.  So once dnscahe
has received 200 distinct queries from the time it was started, it
will always have 199 (briefly) or 200 UDP sockets open.


paul
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.