Re: Quick Poll: Would you trust system software from an anonymous source?
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 12 Mar 2010, Paul Jarc wrote: > Dean Anderson <[email protected]> wrote: > > If the records happen to exist, then its just like the RFC described as > > example: Spoofing wrong NXdomain is possible. But If they don't exist, > > then spoofing NXDomain is still possible. We knew that before. > > Spoofing NXDOMAIN has nothing to do with Kaminsky's attack. The > forged answers may or may not be NXDOMAIN; it's irrelevant. The > geniune answer may or may not be NXDOMAIN; it's also irrelevant. Yes it does. Kaminsky just put it in terms of trying multiple QNames that don't exist to find names that aren't in the cache, for an opportunity to poison with bad glue. That is spoofing NXDomain replies. In 2006, servers were being tested against glue spoofing. > > It took 26 million packets in January 2008 to spoof dnscache. It > > takes 26 million packets to spoof dnscache now. There was no > > (non-gratuitous) change and no discovery. > > Kaminsky didn't reduce the number of packets required. He reduced the > time required. Nope. Didn't do that either. The time depends on the rate at which packets are sent. Kaminsky didn't invent a way to send packets faster. > Before, when one attempt failed and the geniune answer was cached, the > attacker would havev to wait out the TTL, then try again. I don't know when we determined (wrongly) that you had to wait for the TTL to time out when spoofing non-cached records. Before NXDomain, non-existant records would take the longest, and give the attacker the most time to spoof. So that's what anyone would try. IF there was indeed some fallacy among crackers about TTL, exposing the fallacy to crackers is also no scientific discovery. For example, Some "crackers" thought open relays were anonymous. I revealed that fallacy to them by tracking them down. I only cite the discovery of their actual identity, and don't claim to have "discovered" that open relays weren't anonymous. > Kaminsky's new technique was to immediately move on to a different > qname rather than waiting. Of course that was always possible, but as > far as I know, no one had done it before (discovery, not invention). > Do you have references of anyone earlier sidestepping the TTL-wait by > moving on to a different qname? That's not a new technique. We knew about this "feature" in 1998 and before. NXDomain was //invented// to improve performance in the non-malicous case. It was the motivation for RFC2308 in 1998: Negative caching is useful as it reduces the response time for negative answers. It also reduces the number of messages that have to be sent between resolvers and name servers hence overall network traffic. A large proportion of DNS traffic on the Internet could be eliminated if all resolvers implemented negative caching. With this in mind negative caching should no longer be seen as an optional part of a DNS resolver. If you are trying to inject bad glue, not any particular record, then a non-cached NXDomain is the //obvious// choice. That is no discovery. Doing this does not speed up the attack. Perhaps crackers thought it was harder than it is, but I've been telling people its easy for a long time. So have others. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 256 5494