Re: update on the djbdns bugs? (fwd)

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
---------- Forwarded message ----------
Date: Wed, 8 Oct 2008 04:55:44 -0400 (EDT)
From: Dean Anderson <[email protected]>
To: Dan Kaminsky <[email protected]>
Cc: Kevin Day <[email protected]>, [email protected]
Subject: Re: update on the djbdns bugs?

On Sat, 4 Oct 2008, Dan Kaminsky wrote:

> For all future communications, I am going to ignore your attitude and
> stick to the facts.  More Biden, less Palin.

Bullshitters annoy me.

> Dean, I was using simple roulette logic.  65,536 ports * 65,536 qids /
> 200 simultaneously valid responses = 21M.  We're dealing in orders of
> magnitudes, it's a reasonable approximation.

You still seem to be channeling Palin:

(%i69) 65536 * 65536 * 200;
(%o69)                           858993459200

Quite a bit higher than 21M.  21M is indeed close to the right number by
an order of magnitude. But I think your number is made up. Maybe you
heard the right number at some point, but couldn't remember it 
exactly... or maybe you just guessed. I don't know. But you have no 
credible explanation for your math.

> The reason we have 200 simultaneous outstanding requests is that,
> without them there aren't 200 simultaneously valid responses.  To
> continue the birthday paradox analogy, if we require that there's only
> one kid in the room at a time while looking for collisions, the odds of
> a shared birthday drop to 1/365.

Yep, I did figure that out (no thanks to you), and I made the correct
calculations.

> Kevin, Dean is claiming that there's some code that prevents
> simultaneous outstanding queries for the same name, at least to the same
> host.  Would you mind responding with a trace that shows otherwise?  If
> Dean is correct, then the damage from non-birthday-protection drops
> pretty substantially, from MAXUDP to the number of NS's.

Well, one probably can't get this attack to work unless a nameserver are
down, since one needs to send 28 million packets to be successful.
Second, nameservers are queried in random order, so one of the first few
queries will hit a working server unless all servers are down.  


> The reason you share ports is precisely to make the port random, rather
> than exhaustable.  There are DNS stacks that won't allow multiple
> outstanding QID's with the same number, and they're problematic.  The
> other way to prevent exhaustion is to just not have MAXUDP==65536.

Wrong. If you share ports, then you have to look for a valid query id
for _ANY_ response on a correct port.  This greatly increases the odds
of a collision, because then a correct port will have multiple possible
correct queryids, instead of exactly one.  Are you trying to engineer
weakness?

		--Dean

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.