Re: z/OS BIND9 DNS Vulnerable to Cache Poisoning Attack Problem?



On 4 Aug 2008 13:58:04 -0700,
edjaffe@xxxxxxxxxxxxxxxxxxx (Edward Jaffe) wrote:

52% of servers being tested at Kaminsky's site --
http://www.doxpara.com/ -- are still vulnerable. (This includes my home
broadband ISP cox.net. :-( )

Kaminsky alleges that "far more than 52% of [DNS] servers are vulnerable".

It appears that Kaminsky's test protocol is to send some number of DNS
queries to a target name server, and then see how many *different*
source ports come back in the response packets. Where that number is
small (or worst-case, always the same), the protocol assumes a
vulnerable name server.

However, if Kaminsky's protocol is not *also* checking to see whether
the response was recursive, his numbers might overstate the percentage
of servers that are actually vulnerable. A name server that does not
cache (a completely non-recursive server, for example) is not
vulnerable to cache-poisoning attacks, even though it might always
send responses on the same source port.

My comments are not meant to minize the overall seriousness of cache
poisoning vulnerability.

Eric

--
Eric Chevalier E-mail: etech@xxxxxxxxxxxxxxxx
Web: www.tulsagrammer.com
Is that call really worth your child's life? HANG UP AND DRIVE!
.



Relevant Pages

  • [REVS] Introduction to HTTP Response Splitting
    ... single HTTP request that forces the web server to form an output stream, ... one response. ... HTTP response splitting is a fairly new web application vulnerability. ... Web cache poisoning: In this form a rather larger defacement takes place ...
    (Securiteam)
  • [NT] Unchecked Buffer in Gopher Protocol Handler Can Run Code of Attackers Choice
    ... protect themselves against a publicly disclosed vulnerability until ... The Gopher protocol is a legacy protocol that provides for the transfer of ... Information on Gopher servers ... attack through a specially crafted server response. ...
    (Securiteam)
  • Re: SslStream Read Problem
    ... System.Net.Sockets.TcpClient and POP protocol. ... nBytesRead = stream.Read; ... which sends a small message and the server ... I can now read the response from GMail's pop server. ...
    (microsoft.public.dotnet.languages.csharp)
  • What does this mean ? message does not conform
    ... Meringue', Account: 'nn_Earthlink', Server: ... 'smtpauth.earthlink.net', Protocol: SMTP, Server ... Response: '550 Your message does not conform to ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: how to handle socket timeout?
    ... like server congested or server ... of timeouts to limit the response time is not recommended, ... You should follow the specifications for the protocol you ... Various request and response formats. ...
    (comp.unix.programmer)

Loading