Re: Quick Poll: Would you trust system software from an anonymous source?

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Thu, 11 Mar 2010, Paul Jarc wrote:

> Dean Anderson <[email protected]> wrote:
> > I'd have to see what it looks like after taking out
> > the references to "Kaminsky-class" cache poisoning, and the Kaminsky
> > non-discovery. That is plagarism because Kaminsky didn't discover that.
> 
> My understanding is that while the attack he described did use some
> existing techniques, he also introduced one new technique: querying
> for sequential names, so that if one poisoning attempt failed, the
> attacker could immediately try again with a new query name, rather
> than waiting for the genuine cached record to expire from the cache.

Nope. This is a known flaw of NXDomain "security".  RFC2308 security
considerations section actually describes spoofing attacks using
NXDOMAIN.  So this attack was known in 1998.

I posted this to DJBDNS Oct 9, 2008.  You ignore my posts at your own
peril to getting facts.

		--Dean

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 256 5494
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.