Re: Dishonest Forks? | Was - Re: [Namedroppers-honest] Brian Smith asks: Who is Dean Anderson?
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 11 Mar 2010, Matthew Dempsky wrote: > On Thu, Mar 11, 2010 at 3:13 PM, Dean Anderson <[email protected]> wrote: > > Yes there is a time restriction > > There is a time restriction on how long before an outstanding query > receives a legitimate response packet, but that only affects how many > queries an attacker has to send to dnscache to keep it maxed out on > duplicate outstanding queries. E.g., if queries receive a response on > average in 100ms, then an attacker has to send an average of 2000 > queries per second to keep dnscache at 200 concurrent outstanding > queries; if it's 50ms, then it takes 4000 queries per second; if it's > 200ms, then it takes only 1000 queries per second. > > However, this has no impact on the expected number of forged response > packets needed before success, or on how long an attacker can sustain > an attack. What you describe keeps all the ports open. But when the legitimate server responds with the legitimate responses (all probably in ~100ms or so), each of those 200 ports will close. For example, Attacker starts with query x1.av8.net. To get a collision, he need 26 million packets (on Query x1.av8.net) before the ports close. In about ~100 ms, the av8.net will respond with the real nxdomains for those 200 outstanding queries. The attacker must start over with a different query x2.av8.net; again trying to hit the collision. Continuing to send packets to spoof x1.av8.net after the real nxdomains are received is a waste of effort. Sending more queries of the x1.av8.net name are answered out of cache, and have no chance of spoof, no matter how many queries per second you send. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 256 5494