Re: Quick Poll: Would you trust system software from an anonymous source?
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Sat, 13 Mar 2010, Paul Jarc wrote: > Dean Anderson <[email protected]> wrote: > > On Fri, 12 Mar 2010, Paul Jarc wrote: > >> Spoofing NXDOMAIN has nothing to do with Kaminsky's attack. The > >> forged answers may or may not be NXDOMAIN; it's irrelevant. The > >> geniune answer may or may not be NXDOMAIN; it's also irrelevant. > > > > Yes it does. Kaminsky just put it in terms of trying multiple QNames > > that don't exist to find names that aren't in the cache, for an > > opportunity to poison with bad glue. > > The nonexistence of those domains is incidental. Their absence from > the cache is what matters. That's what I mean by NXDOMAIN being > irrelevant. You can't spoof NXDOMAIN if they are in the cache already. Duh. > Fine, you can describe it that way. But my point is that it's not at > all the attack described in RFC2308 that you referred to. The attack > in the RFC consists of sending a forged answer that claims NXDOMAIN > for a domain that actually exists, as a sort of denial of service. Yes. So we knew that things not in the cache could be spoofed, and that NXDOMAIN was no security benefit; just a performance benefit. In 2006, people were testing for bad glue. > >> Before, when one attempt failed and the geniune answer was cached, the > >> attacker would havev to wait out the TTL, then try again. > > > > I don't know when we determined (wrongly) that you had to wait for the > > TTL to time out when spoofing non-cached records. > > Reread my statement that you quoted, particularly "the geniune answer > was cached". I'm not saying that you have to wait out the TTL for a > *non*-cached record. Neither am I. I'm saying you don't have to wait for the record to expire in anycase. The notion that you have wait for TTL to expire for a cached record is/was foolish. There are lots of ways to get records out of cache before they expire. Just making lots of NXDOMAIN queries for records that don't exist will fill the cache with NXDOMAIN answers and the record you want to spoof will be removed from the cache. Wait, my phone is ringing: Paul Vixie: "Dean, I'm speaking to you on an unsecure phone. This is big news. I'm going to have Dan Kaminsky alert the media and tell people to switch to OpenDNS. Don't ever talk about this on an unsecure line" When you are spoofing bad glue, we know that any record with glue will do. We knew this in 2006, and were testing for it. > >> Kaminsky's new technique was to immediately move on to a different > >> qname rather than waiting. > ... > > That's not a new technique. We knew about this "feature" in 1998 and > > before. NXDomain was //invented// to improve performance in the > > non-malicous case. > > So do you have references of malicious cases from that time? > Specifically, using sequential QNAMEs, not just a single non-existent > QNAME? No. But then, I have no references to malicious abuse of open recursors before October 2005, when Kaminsky reported finding 500,000 to Schmoo-con. I think a review of the archives is in order though. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 256 5494