Re: Quick Poll: Would you trust system software from an anonymous source?
[email protected] (Paul Jarc)
| Newsgroups | gmane.network.djbdns |
|---|---|
| Organization | What did you have in mind? A short, blunt, human pyramid? |
| Message-ID | <[email protected]> |
Dean Anderson <[email protected]> wrote: > On Thu, 11 Mar 2010, Paul Jarc wrote: >> My understanding is that while the attack he described did use some >> existing techniques, he also introduced one new technique: querying >> for sequential names, so that if one poisoning attempt failed, the >> attacker could immediately try again with a new query name, rather >> than waiting for the genuine cached record to expire from the cache. > > Nope. This is a known flaw of NXDomain "security". RFC2308 security > considerations section actually describes spoofing attacks using > NXDOMAIN. So this attack was known in 1998. That section describes sending a forged NXDOMAIN response to fool a cache into thinking the QNAME does not exist. It doesn't mention anything about iterating through multiple QNAMEs to get better odds of poisoning through glue. paul