Re: djbdns: Current recommended patches? (fwd)

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
The message below should discredit Dempsky's credibility; I told him and
others about the "consistency in spoofing" last year.  

As a memory aid, please call the patch the "King/Kaminsky/Day Consistent
Spoofing" patch.  Aids spoofers from getting caught in inconsistent
spoofs. It does nothing to prevent birthday attack, which can't be
prevented in UDP.  Whenever someone says they can prevent birthday
attacks in UDP DNS, tell them they are full of shit.

Without this patch, it would be nearly impossible to consistently spoof
DNS for things like login or other events that result in a flurry of
repeated identical queries with different ports and QIDs. It would be
just about impossible to spoof 4 or 5 queries * 26 million packet per
query to spoof.

They know very well they are wrong, and they know how they are wrong.  
Its just a complete waste of time to rehash this.

As I said before: its quite simple:

1. There was no "discovery" of any vulnerability by either Day or 
   Kaminsky.  Multiple sources confirm that fact. I can explain the 
   math, but you still don't understand the math.

2. There is no credible fix for such non-discovery. The changes are
   gratuitous or worse than gratuitous. Math (that you don't understand)
   shows them to be worse.

3. The mere fact of that someone is anonymously purveying these changes 
   is discrediting by itself.

This is enough for any responsible system administrator to make a
decision.

Enough already.

		--Dean

---------- Forwarded message ----------
Date: Tue, 19 May 2009 21:37:53 -0400 (EDT)
From: Dean Anderson <[email protected]>
To: Matthew Dempsky <[email protected]>
Cc: David Nicol <[email protected]>,
     Andrew Richards <[email protected]>, [email protected]
Subject: Re: djbdns: Current recommended patches?

This is of historical interest only.

The Kaminsky/Day/King patches make no distinction between inadvertent
and intentional query repetition.  All repetition is removed. Their
patches ensure that all clients consistently receive the spoofed packet,
which wouldn't likely happen without the patches.

I will also post the offlist discussion with Kaminsky & Day of the
earlier (related) patch scheme to alter DNS servers to fix the so-called
Kaminsky 'bug'/scam)  That earlier scheme, (NOT implemented in the first
set of DJBDNS patches though I haven't checked the second set of
patches), enabled a spoof in about 1000 tries.

		--Dean


On Tue, 19 May 2009, Matthew Dempsky
wrote:

> On Tue, May 19, 2009 at 5:19 PM, David Nicol <[email protected]> wrote:
> > http://cr.yp.to/djbdns/forgery.html specifies "query repetition" as an
> > effective mechanism to prevent forgery.  By merging identical outgoing
> > requests, one ceases to repeat queries.
> 
> That's a different kind of query repetition.
> 
> Jeff King's patches eliminate *inadvertent* query repetition; i.e.,
> where dnscache coincidentally sends multiple queries for a single
> name/type at once, improving the chances for an attacker to forge a
> response to one of them.
> 
> On forgery.html, Dan is talking about *intentional* query repetition;
> i.e., having a cache send a query multiple times and checking that the
> results are "the same".  (Defining "the same" is heuristic at best,
> because DNS makes no guarantees that two queries for the same name
> will return the same response.)
> 
> 

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.