Re: okay already

Dean Anderson <[email protected]> Thu, 25 Mar 2010 12:13:17 -0400 (EDT)
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
And also on unpatched BIND.  BIND was already well known to use only one
port (no guessing), and a brute force attack of all 65536 possible QIDs
was easily possible on a lan.  That vulnerablity was the reason DJB
created dnscache:  Vixie wouldn't fix BIND.  All this was well known, as
were the efforts required. Kaminsky did not find anything that speeds up
the attack on BIND or anything else.

FYI, (I missed this on the first look) the CERT cited by Loftis is not
the most recent CERT on BIND by Kaminsky.  Kaminsky's CERT is
http://www.kb.cert.org/vuls/id/800113

The CERT Loftis just cited, http://www.kb.cert.org/vuls/id/457875, was
from 2002, and also explains the birthday attack. Actaully, that is
another reference showing that Kaminsky didn't discover anything
whatsoever.

The 2002 CERT has a table which for DJBDNS, comes into the right
ballpark:  (I had to relabel the headings a little)

| random bits to guess   | outstanding requests | 50% success #packets
[...]
| TID only (16bits)      |  unlimited           | 426       [BIND]
[...]
| TID and port (32 bits) |  200                 | 15 million [DJBDNS]
[...]

I'm not certain that BIND allowed unlimited requests. The 2002 CERT also
was lists several implementations as being invulnerable.  It is unclear
what criteria was used to decide some implementations invulnerable.
(adns, Check Point, GNU glibc, Network Appliance, Xerox Corporation were
listed a 'Not Vulnerable'. All implmentations are vulnerable; its just a
question of how many packets one has to send to succeed.  Perhaps some
level of effort was decided to be "too high".  When you have to send
millions of packets, that's probably "too high" for practical purposes.


This quote is appropo:

  "The 'birthday attack' method described here appears to be reasonably 
   well known in the DNS developer community, but we have been unable 
   to find significant public discussion of it and are thus documenting
   it here."

Apparently they missed the abuse of Bernstein on namedroppers when he
tried to discuss it, and the efforts by Vixie et al to quell anything
that was 'critical of BIND'.  Or perhaps, their report just implies that
Vixie was successful at quelling the discussion of these attacks.

		--Dean


On Thu, 25 Mar 2010, Sebastian Andersson wrote:

> On Wed, Mar 24, 2010 at 01:04:42PM -0600, Michael Loftis wrote:
> > Unpatched DJBDNS, because it will send out many queries for the same data, 
> > is somewhere around 200x more likely to fall prey to cache poisoning.  No 
> > nefarious smoke and mirrors, nothing of the sort.  It's been very clearly 
> > explained, the math was checked by real statisticians before and after the 
> > fact and found to be sound.  There's no way to precisely measure these 
> > things, but they certainly can be estimated, in a number of ways.
> 
> Can't one simply run metasploit's DNS poisoning module against djbdns
> (on a lan to speed up the results) before and after the patch is applied
> and measure the time differences?
> 
> /Sebastian
> 

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 256 5494