Re: update on the djbdns bugs? (fwd)
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
---------- Forwarded message ---------- Date: Wed, 8 Oct 2008 04:55:44 -0400 (EDT) From: Dean Anderson <[email protected]> To: Dan Kaminsky <[email protected]> Cc: Kevin Day <[email protected]>, [email protected] Subject: Re: update on the djbdns bugs? On Sat, 4 Oct 2008, Dan Kaminsky wrote: > For all future communications, I am going to ignore your attitude and > stick to the facts. More Biden, less Palin. Bullshitters annoy me. > Dean, I was using simple roulette logic. 65,536 ports * 65,536 qids / > 200 simultaneously valid responses = 21M. We're dealing in orders of > magnitudes, it's a reasonable approximation. You still seem to be channeling Palin: (%i69) 65536 * 65536 * 200; (%o69) 858993459200 Quite a bit higher than 21M. 21M is indeed close to the right number by an order of magnitude. But I think your number is made up. Maybe you heard the right number at some point, but couldn't remember it exactly... or maybe you just guessed. I don't know. But you have no credible explanation for your math. > The reason we have 200 simultaneous outstanding requests is that, > without them there aren't 200 simultaneously valid responses. To > continue the birthday paradox analogy, if we require that there's only > one kid in the room at a time while looking for collisions, the odds of > a shared birthday drop to 1/365. Yep, I did figure that out (no thanks to you), and I made the correct calculations. > Kevin, Dean is claiming that there's some code that prevents > simultaneous outstanding queries for the same name, at least to the same > host. Would you mind responding with a trace that shows otherwise? If > Dean is correct, then the damage from non-birthday-protection drops > pretty substantially, from MAXUDP to the number of NS's. Well, one probably can't get this attack to work unless a nameserver are down, since one needs to send 28 million packets to be successful. Second, nameservers are queried in random order, so one of the first few queries will hit a working server unless all servers are down. > The reason you share ports is precisely to make the port random, rather > than exhaustable. There are DNS stacks that won't allow multiple > outstanding QID's with the same number, and they're problematic. The > other way to prevent exhaustion is to just not have MAXUDP==65536. Wrong. If you share ports, then you have to look for a valid query id for _ANY_ response on a correct port. This greatly increases the odds of a collision, because then a correct port will have multiple possible correct queryids, instead of exactly one. Are you trying to engineer weakness? --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000