Re: Quick Poll: Would you trust system software from an anonymous source?

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Fri, 12 Mar 2010, Paul Jarc wrote:

> Dean Anderson <[email protected]> wrote:
> > If the records happen to exist, then its just like the RFC described as
> > example:  Spoofing wrong NXdomain is possible. But If they don't exist,
> > then spoofing NXDomain is still possible. We knew that before.
> 
> Spoofing NXDOMAIN has nothing to do with Kaminsky's attack.  The
> forged answers may or may not be NXDOMAIN; it's irrelevant.  The
> geniune answer may or may not be NXDOMAIN; it's also irrelevant.

Yes it does. Kaminsky just put it in terms of trying multiple QNames
that don't exist to find names that aren't in the cache, for an
opportunity to poison with bad glue.  That is spoofing NXDomain replies.  
In 2006, servers were being tested against glue spoofing.

> > It took 26 million packets in January 2008 to spoof dnscache. It
> > takes 26 million packets to spoof dnscache now.  There was no
> > (non-gratuitous) change and no discovery.
> 
> Kaminsky didn't reduce the number of packets required.  He reduced the
> time required.

Nope. Didn't do that either. The time depends on the rate at which
packets are sent. Kaminsky didn't invent a way to send packets faster.

> Before, when one attempt failed and the geniune answer was cached, the
> attacker would havev to wait out the TTL, then try again.

I don't know when we determined (wrongly) that you had to wait for the
TTL to time out when spoofing non-cached records.  Before NXDomain, 
non-existant records would take the longest, and give the attacker the 
most time to spoof.  So that's what anyone would try.

IF there was indeed some fallacy among crackers about TTL, exposing the
fallacy to crackers is also no scientific discovery.

For example, Some "crackers" thought open relays were anonymous.  I
revealed that fallacy to them by tracking them down.  I only cite the
discovery of their actual identity, and don't claim to have "discovered"
that open relays weren't anonymous.

> Kaminsky's new technique was to immediately move on to a different
> qname rather than waiting.  Of course that was always possible, but as
> far as I know, no one had done it before (discovery, not invention).  
> Do you have references of anyone earlier sidestepping the TTL-wait by
> moving on to a different qname?

That's not a new technique.  We knew about this "feature" in 1998 and
before.  NXDomain was //invented// to improve performance in the
non-malicous case.  It was the motivation for RFC2308 in 1998:

   Negative caching is useful as it reduces the response time for
   negative answers.  It also reduces the number of messages that have
   to be sent between resolvers and name servers hence overall network
   traffic.  A large proportion of DNS traffic on the Internet could be
   eliminated if all resolvers implemented negative caching.  With this
   in mind negative caching should no longer be seen as an optional part
   of a DNS resolver.

If you are trying to inject bad glue, not any particular record, then a
non-cached NXDomain is the //obvious// choice. That is no discovery.  
Doing this does not speed up the attack.  Perhaps crackers thought it
was harder than it is, but I've been telling people its easy for a long
time. So have others.

		--Dean

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 256 5494
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.