Re: Quick Poll: Would you trust system software from an anonymous source?

[email protected] (Paul Jarc)
Newsgroups gmane.network.djbdns
Organization What did you have in mind? A short, blunt, human pyramid?
Message-ID <[email protected]>
Dean Anderson <[email protected]> wrote:
> On Thu, 11 Mar 2010, Paul Jarc wrote:
>> My understanding is that while the attack he described did use some
>> existing techniques, he also introduced one new technique: querying
>> for sequential names, so that if one poisoning attempt failed, the
>> attacker could immediately try again with a new query name, rather
>> than waiting for the genuine cached record to expire from the cache.
>
> Nope. This is a known flaw of NXDomain "security".  RFC2308 security
> considerations section actually describes spoofing attacks using
> NXDOMAIN.  So this attack was known in 1998.

That section describes sending a forged NXDOMAIN response to fool a
cache into thinking the QNAME does not exist.  It doesn't mention
anything about iterating through multiple QNAMEs to get better odds of
poisoning through glue.


paul
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.