Re: djbdns: Current recommended patches? (fwd)
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
The message below should discredit Dempsky's credibility; I told him and others about the "consistency in spoofing" last year. As a memory aid, please call the patch the "King/Kaminsky/Day Consistent Spoofing" patch. Aids spoofers from getting caught in inconsistent spoofs. It does nothing to prevent birthday attack, which can't be prevented in UDP. Whenever someone says they can prevent birthday attacks in UDP DNS, tell them they are full of shit. Without this patch, it would be nearly impossible to consistently spoof DNS for things like login or other events that result in a flurry of repeated identical queries with different ports and QIDs. It would be just about impossible to spoof 4 or 5 queries * 26 million packet per query to spoof. They know very well they are wrong, and they know how they are wrong. Its just a complete waste of time to rehash this. As I said before: its quite simple: 1. There was no "discovery" of any vulnerability by either Day or Kaminsky. Multiple sources confirm that fact. I can explain the math, but you still don't understand the math. 2. There is no credible fix for such non-discovery. The changes are gratuitous or worse than gratuitous. Math (that you don't understand) shows them to be worse. 3. The mere fact of that someone is anonymously purveying these changes is discrediting by itself. This is enough for any responsible system administrator to make a decision. Enough already. --Dean ---------- Forwarded message ---------- Date: Tue, 19 May 2009 21:37:53 -0400 (EDT) From: Dean Anderson <[email protected]> To: Matthew Dempsky <[email protected]> Cc: David Nicol <[email protected]>, Andrew Richards <[email protected]>, [email protected] Subject: Re: djbdns: Current recommended patches? This is of historical interest only. The Kaminsky/Day/King patches make no distinction between inadvertent and intentional query repetition. All repetition is removed. Their patches ensure that all clients consistently receive the spoofed packet, which wouldn't likely happen without the patches. I will also post the offlist discussion with Kaminsky & Day of the earlier (related) patch scheme to alter DNS servers to fix the so-called Kaminsky 'bug'/scam) That earlier scheme, (NOT implemented in the first set of DJBDNS patches though I haven't checked the second set of patches), enabled a spoof in about 1000 tries. --Dean On Tue, 19 May 2009, Matthew Dempsky wrote: > On Tue, May 19, 2009 at 5:19 PM, David Nicol <[email protected]> wrote: > > http://cr.yp.to/djbdns/forgery.html specifies "query repetition" as an > > effective mechanism to prevent forgery. Â By merging identical outgoing > > requests, one ceases to repeat queries. > > That's a different kind of query repetition. > > Jeff King's patches eliminate *inadvertent* query repetition; i.e., > where dnscache coincidentally sends multiple queries for a single > name/type at once, improving the chances for an attacker to forge a > response to one of them. > > On forgery.html, Dan is talking about *intentional* query repetition; > i.e., having a cache send a query multiple times and checking that the > results are "the same". (Defining "the same" is heuristic at best, > because DNS makes no guarantees that two queries for the same name > will return the same response.) > > -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000