Re: djbdns: Current recommended patches?
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
This is of historical interest only. The Kaminsky/Day/King patches make no distinction between inadvertent and intentional query repetition. All repetition is removed. Their patches ensure that all clients consistently receive the spoofed packet, which wouldn't likely happen without the patches. I will also post the offlist discussion with Kaminsky & Day of the earlier (related) patch scheme to alter DNS servers to fix the so-called Kaminsky 'bug'/scam) That earlier scheme, (NOT implemented in the first set of DJBDNS patches though I haven't checked the second set of patches), enabled a spoof in about 1000 tries. --Dean On Tue, 19 May 2009, Matthew Dempsky wrote: > On Tue, May 19, 2009 at 5:19 PM, David Nicol <[email protected]> wrote: > > http://cr.yp.to/djbdns/forgery.html specifies "query repetition" as an > > effective mechanism to prevent forgery. Â By merging identical outgoing > > requests, one ceases to repeat queries. > > That's a different kind of query repetition. > > Jeff King's patches eliminate *inadvertent* query repetition; i.e., > where dnscache coincidentally sends multiple queries for a single > name/type at once, improving the chances for an attacker to forge a > response to one of them. > > On forgery.html, Dan is talking about *intentional* query repetition; > i.e., having a cache send a query multiple times and checking that the > results are "the same". (Defining "the same" is heuristic at best, > because DNS makes no guarantees that two queries for the same name > will return the same response.) > > -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000