Re: Quick Poll: Would you trust system software from an anonymous source?
[email protected] (Paul Jarc)
| Newsgroups | gmane.network.djbdns |
|---|---|
| Organization | What did you have in mind? A short, blunt, human pyramid? |
| Message-ID | <[email protected]> |
Dean Anderson <[email protected]> wrote: > If the records happen to exist, then its just like the RFC described as > example: Spoofing wrong NXdomain is possible. But If they don't exist, > then spoofing NXDomain is still possible. We knew that before. Spoofing NXDOMAIN has nothing to do with Kaminsky's attack. The forged answers may or may not be NXDOMAIN; it's irrelevant. The geniune answer may or may not be NXDOMAIN; it's also irrelevant. > It took 26 million packets in January 2008 to spoof dnscache. It > takes 26 million packets to spoof dnscache now. There was no > (non-gratuitous) change and no discovery. Kaminsky didn't reduce the number of packets required. He reduced the time required. Before, when one attempt failed and the geniune answer was cached, the attacker would havev to wait out the TTL, then try again. Kaminsky's new technique was to immediately move on to a different qname rather than waiting. Of course that was always possible, but as far as I know, no one had done it before (discovery, not invention). Do you have references of anyone earlier sidestepping the TTL-wait by moving on to a different qname? paul