Re: Quick Poll: Would you trust system software from an anonymous source?
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 11 Mar 2010, Paul Jarc wrote: > Dean Anderson <[email protected]> wrote: > > On Thu, 11 Mar 2010, Paul Jarc wrote: > >> My understanding is that while the attack he described did use some > >> existing techniques, he also introduced one new technique: querying > >> for sequential names, so that if one poisoning attempt failed, the > >> attacker could immediately try again with a new query name, rather > >> than waiting for the genuine cached record to expire from the cache. > > > > Nope. This is a known flaw of NXDomain "security". RFC2308 security > > considerations section actually describes spoofing attacks using > > NXDOMAIN. So this attack was known in 1998. > > That section describes sending a forged NXDOMAIN response to fool a > cache into thinking the QNAME does not exist. It doesn't mention > anything about iterating through multiple QNAMEs to get better odds of > poisoning through glue. It talks about spoofing NXDomain responses, which you obviously get by steping through QNAMEs that don't exist. The particular case of spoofing glue was something people tested for in 2006 and before. It was known then exactly what the problems spoofing glue caused. There is nothing novel in combining spoofed NXDomain, a known problem since 1998, with bad glue, another known problem since before 2006. This isn't a discovery. Its a "media hack". --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 256 5494