Re: okay already
Dean Anderson <[email protected]> Thu, 25 Mar 2010 12:13:17 -0400 (EDT)
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
And also on unpatched BIND. BIND was already well known to use only one port (no guessing), and a brute force attack of all 65536 possible QIDs was easily possible on a lan. That vulnerablity was the reason DJB created dnscache: Vixie wouldn't fix BIND. All this was well known, as were the efforts required. Kaminsky did not find anything that speeds up the attack on BIND or anything else. FYI, (I missed this on the first look) the CERT cited by Loftis is not the most recent CERT on BIND by Kaminsky. Kaminsky's CERT is http://www.kb.cert.org/vuls/id/800113 The CERT Loftis just cited, http://www.kb.cert.org/vuls/id/457875, was from 2002, and also explains the birthday attack. Actaully, that is another reference showing that Kaminsky didn't discover anything whatsoever. The 2002 CERT has a table which for DJBDNS, comes into the right ballpark: (I had to relabel the headings a little) | random bits to guess | outstanding requests | 50% success #packets [...] | TID only (16bits) | unlimited | 426 [BIND] [...] | TID and port (32 bits) | 200 | 15 million [DJBDNS] [...] I'm not certain that BIND allowed unlimited requests. The 2002 CERT also was lists several implementations as being invulnerable. It is unclear what criteria was used to decide some implementations invulnerable. (adns, Check Point, GNU glibc, Network Appliance, Xerox Corporation were listed a 'Not Vulnerable'. All implmentations are vulnerable; its just a question of how many packets one has to send to succeed. Perhaps some level of effort was decided to be "too high". When you have to send millions of packets, that's probably "too high" for practical purposes. This quote is appropo: "The 'birthday attack' method described here appears to be reasonably well known in the DNS developer community, but we have been unable to find significant public discussion of it and are thus documenting it here." Apparently they missed the abuse of Bernstein on namedroppers when he tried to discuss it, and the efforts by Vixie et al to quell anything that was 'critical of BIND'. Or perhaps, their report just implies that Vixie was successful at quelling the discussion of these attacks. --Dean On Thu, 25 Mar 2010, Sebastian Andersson wrote: > On Wed, Mar 24, 2010 at 01:04:42PM -0600, Michael Loftis wrote: > > Unpatched DJBDNS, because it will send out many queries for the same data, > > is somewhere around 200x more likely to fall prey to cache poisoning. No > > nefarious smoke and mirrors, nothing of the sort. It's been very clearly > > explained, the math was checked by real statisticians before and after the > > fact and found to be sound. There's no way to precisely measure these > > things, but they certainly can be estimated, in a number of ways. > > Can't one simply run metasploit's DNS poisoning module against djbdns > (on a lan to speed up the results) before and after the patch is applied > and measure the time differences? > > /Sebastian > -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 256 5494