Re: Quick Poll: Would you trust system software from an anonymous source?

[email protected] (Paul Jarc)
Newsgroups gmane.network.djbdns
Organization What did you have in mind? A short, blunt, human pyramid?
Message-ID <[email protected]>
Dean Anderson <[email protected]> wrote:
> I'd have to see what it looks like after taking out
> the references to "Kaminsky-class" cache poisoning, and the Kaminsky
> non-discovery. That is plagarism because Kaminsky didn't discover that.

My understanding is that while the attack he described did use some
existing techniques, he also introduced one new technique: querying
for sequential names, so that if one poisoning attempt failed, the
attacker could immediately try again with a new query name, rather
than waiting for the genuine cached record to expire from the cache.
(Since the poison is for an in-bailiwick but unasked-for record, it
doesn't matter what record is asked for, and so different records can
be asked for in different attempts.)  Are you saying that this
particular technique was also not original?  Do you have references of
its previous use?


paul
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.