Re: Quick Poll: Would you trust system software from an anonymous source?
[email protected] (Paul Jarc)
| Newsgroups | gmane.network.djbdns |
|---|---|
| Organization | What did you have in mind? A short, blunt, human pyramid? |
| Message-ID | <[email protected]> |
Dean Anderson <[email protected]> wrote: > On Fri, 12 Mar 2010, Paul Jarc wrote: >> Spoofing NXDOMAIN has nothing to do with Kaminsky's attack. The >> forged answers may or may not be NXDOMAIN; it's irrelevant. The >> geniune answer may or may not be NXDOMAIN; it's also irrelevant. > > Yes it does. Kaminsky just put it in terms of trying multiple QNames > that don't exist to find names that aren't in the cache, for an > opportunity to poison with bad glue. The nonexistence of those domains is incidental. Their absence from the cache is what matters. That's what I mean by NXDOMAIN being irrelevant. > That is spoofing NXDomain replies. Fine, you can describe it that way. But my point is that it's not at all the attack described in RFC2308 that you referred to. The attack in the RFC consists of sending a forged answer that claims NXDOMAIN for a domain that actually exists, as a sort of denial of service. >> Before, when one attempt failed and the geniune answer was cached, the >> attacker would havev to wait out the TTL, then try again. > > I don't know when we determined (wrongly) that you had to wait for the > TTL to time out when spoofing non-cached records. Reread my statement that you quoted, particularly "the geniune answer was cached". I'm not saying that you have to wait out the TTL for a *non*-cached record. >> Kaminsky's new technique was to immediately move on to a different >> qname rather than waiting. ... > That's not a new technique. We knew about this "feature" in 1998 and > before. NXDomain was //invented// to improve performance in the > non-malicous case. So do you have references of malicious cases from that time? Specifically, using sequential QNAMEs, not just a single non-existent QNAME? paul