Re: Dishonest Forks? | Was - Re: [Namedroppers-honest] Brian Smith asks: Who is Dean Anderson?
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 10 Mar 2010, Matthew Dempsky wrote: > On Wed, Mar 10, 2010 at 4:33 PM, Dean Anderson <[email protected]> wrote: > > The piggybacking scheme re-uses ports for multiple queries. > > For the benefit of readers of the list, here's another example of > Dean's misunderstanding of things. Jeff King's patch to dnscache does > not "reuse ports for multiple queries". Instead, before transmitting > an outbound DNS query, a Jeff King's patch modifies dnscache to check > if an outstanding query for the same name/type already exists. If so, > it doesn't send the extra duplicate query, and instead uses the single > response packet as an answer to both queries. Ah yes. I was afraid I would forget some detail. Its the same difference, though. One attack packet can potentially answer several queries. > How this affects the attack Kevin Day pointed out is it eliminates the > benefit an attacker receives by flooding an open dnscache instance > with query packets. If each forged response packet can only match 1 > outstanding query rather than any of up to 200 outstanding queries, > then it's roughly 200x harder for an attacker to forge a response. Except that patch does the exact opposite of this. One successful forged packet, and all waiting responses will get exactly the same (spoofed) answer. The patch ensures consistency in when a spoof is successful. A typical unix system will issue the same query several times during, say a login, from different processes. Unmodified, a spoofer would have to spoof each and every response successfully to have a consistent set of log files. But with Kings patch, no worries. Get one spoof though sucessfully (still takes 26 million packets), and no one will be the wiser. So its worse. > Note also DJB's response to Jeff's patch (from > http://cr.yp.to/djbdns/forgery.html): > > I haven't reviewed the patches that attempt to stop colliding > attacks against dnscache, BIND, etc. Even if these patches work > properly, they are at best a speed bump for blind attackers. > Saying "An attacker has to send billions of packets on average" > is like saying "An attacker has to download a movie"; yes, it > takes a little time, but it's not a serious obstacle. > > He's not outright rejecting it: he's disclaiming that he hasn't > reviewed the patches, and he acknowledges that duplicate-query > suppression can make dnscache more difficult for blind attackers to > poison. > > (Unfortunately, on this page Dan also uses the similar sounding terms > "duplicate-query" and "query repetition", which have very different > security consequences, and Dean fails to distinguish.) I didn't use these terms, so there is no reason for me to distinguish between them. -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 256 5494