Re: Quick Poll: Would you trust system software from an anonymous source?
[email protected] (Paul Jarc)
| Newsgroups | gmane.network.djbdns |
|---|---|
| Organization | What did you have in mind? A short, blunt, human pyramid? |
| Message-ID | <[email protected]> |
Dean Anderson <[email protected]> wrote: > On Thu, 11 Mar 2010, Paul Jarc wrote: >> That section describes sending a forged NXDOMAIN response to fool a >> cache into thinking the QNAME does not exist. It doesn't mention >> anything about iterating through multiple QNAMEs to get better odds of >> poisoning through glue. > > It talks about spoofing NXDomain responses, which you obviously get by > steping through QNAMEs that don't exist. The attack described in the RFC, as its primary goal, makes a geniuinely existing domain seem to not exist. Kaminsky's attack queries for names that probably don't exist, but if they happen to, the attack still works just as well (and the forged answers may or may not be NXDOMAIN, without affecting the result), with the goal of poisoning an unrelated name. These are not at all alike. > The particular case of spoofing glue was something people tested for in > 2006 and before. It was known then exactly what the problems spoofing > glue caused. Right. I'm not claiming that part was novel. As far as I know, Dan hasn't claimed that either. paul