Re: "djbdns and nxdspecial patch"
erwin <[email protected]> Mon, 26 Apr 2010 20:54:26 +0200
| Newsgroups | gmane.network.djbdns |
|---|---|
| Organization | FEHCom |
| Message-ID | <1272308066.2070.6.camel@medusa> |
Hi, a nice article about that issue can (still) be found here: http://www.softpanorama.org/DNS/Security/dns_spoofing.shtml This analysis was first published on SecurityFocus Januray 27, 2003 (the link mentioned on tinydns.org is not working any more). If somebody needs this reference (with some analysis of the PRNG's) feel free to contact me. regards. --eh. Am Montag, den 26.04.2010, 13:43 -0400 schrieb Dean Anderson: > On Fri, 23 Apr 2010, Marco wrote: > > Ok Dean, but the kaminsky bug in djbdns-1.05 exist or not? > > It is Not vulnerable. It takes millions of packets to spoof > djbdns-1.05. So while theoretically possible, its not a practical attack > on djbdns-1.05. This birthday attack was first analyzed around 2002. > http://www.kb.cert.org/vuls/id/457875 Note that it takes at most 32000 > packets to get a 50% success rate on BIND. This fact (the vulnerability > in BIND) was known long before 2002, and was the raison d'et for the > creation of djbdns in the 1990s. Vixie and mafia silenced Bernstein's > discussion of the BIND vulnerability and silenced the obvious fix of > port randomization. So Bernstein wrote djbdns. All other DNS > software except BIND implemented port randomization by 2006. After that, > BIND stood alone and vulnerable. > > > http://www.linuxjournal.com/content/understanding-kaminskys-dns-bug > > The article you quote is one of the first publications during the hoax, > which was perpetrated in June/July 2008. The first publication to > note the hoax was the December 2008 MIT Technology Review. > > The hoax is that all the facts cited by the article (and by Kaminsky et > al) were already known long before July 2008. > > The financial scam is that Kaminsky and Vixie tried to scare people to > change to OpenDNS or a new version of BIND. > > > djbdns is secure from this type of exploit? > > Yes. It takes millions of packets to get a successful exploit, making > this attack impractical. However, with stock djbdns 1.05, one would > still have an opportunity to notice the inconsistent responses. By > checking the logs, one can discover that something was wrong, and > discover what the right answer actually was. > > The King/Day/Kaminsky patches eliminate any inconsistent responses and > thereby prevent the discovery of a successful attack. > > --Dean > -- Dr. Erwin Hoffmann | FEHCom | http://www.fehcom.de
signature.asc
(application/pgp-signature, 197 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEABECAAYFAkvV4V0ACgkQzAMRjn5ANL7CQgCg2OMd0aKXwtJXZJMt4PS6pBcr tAYAn1KloTxoxvzQtqqgFsN0oDgKtL3b =lShJ -----END PGP SIGNATURE-----