Re: Quick Poll: Would you trust system software from an anonymous source?

[email protected] (Paul Jarc)
Newsgroups gmane.network.djbdns
Organization What did you have in mind? A short, blunt, human pyramid?
Message-ID <[email protected]>
Dean Anderson <[email protected]> wrote:
> On Fri, 12 Mar 2010, Paul Jarc wrote:
>> Spoofing NXDOMAIN has nothing to do with Kaminsky's attack.  The
>> forged answers may or may not be NXDOMAIN; it's irrelevant.  The
>> geniune answer may or may not be NXDOMAIN; it's also irrelevant.
>
> Yes it does. Kaminsky just put it in terms of trying multiple QNames
> that don't exist to find names that aren't in the cache, for an
> opportunity to poison with bad glue.

The nonexistence of those domains is incidental.  Their absence from
the cache is what matters.  That's what I mean by NXDOMAIN being
irrelevant.

> That is spoofing NXDomain replies.  

Fine, you can describe it that way.  But my point is that it's not at
all the attack described in RFC2308 that you referred to.  The attack
in the RFC consists of sending a forged answer that claims NXDOMAIN
for a domain that actually exists, as a sort of denial of service.

>> Before, when one attempt failed and the geniune answer was cached, the
>> attacker would havev to wait out the TTL, then try again.
>
> I don't know when we determined (wrongly) that you had to wait for the
> TTL to time out when spoofing non-cached records.

Reread my statement that you quoted, particularly "the geniune answer
was cached".  I'm not saying that you have to wait out the TTL for a
*non*-cached record.

>> Kaminsky's new technique was to immediately move on to a different
>> qname rather than waiting.
...
> That's not a new technique.  We knew about this "feature" in 1998 and
> before.  NXDomain was //invented// to improve performance in the
> non-malicous case.

So do you have references of malicious cases from that time?
Specifically, using sequential QNAMEs, not just a single non-existent
QNAME?


paul
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.