Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Re: "BIND 9 DNS Cache Poisoning" by Amit Klein (Trusteer) Jul 24 2007 05:40PM
securityfocus networkontap com (2 replies)
Re: "BIND 9 DNS Cache Poisoning" by Amit Klein (Trusteer) Jul 24 2007 08:18PM
Jamie Riden (jamie riden gmail com) (2 replies)
Re: "BIND 9 DNS Cache Poisoning" by Amit Klein (Trusteer) Jul 27 2007 04:40AM
Gadi Evron (ge linuxbox org) (2 replies)
This is Paul Vixie's response on this, when I asked him for verification:

-----
this bug has been reported over and over again for a dozen years. it's
odd to have to keep fixing it-- i fixed it in bind4 and bind8 when theo
de raadt offered me his random number generator to use. bind9 should've
used that same one but apparently didn't. note that with this fix, the
difficulty in poisoning someone's cache rises from "a few tens of seconds"
to "a few minutes". it's a 16-bit field. not a lot of room for
randomness or unpredictability. only DNSSEC, a protocol change, fixes
this problem, which is fundamentally a protocol problem. but since folks
just won't leave it alone and keep on reporting it year after decade, we
will keep on improving our random number generator for this dinky little
16-bit field. i just wish the reporters wouldn't be so smarmy and self
congradulatory about it. it's not like this hasn't been reported, and
fixed, many times by many others.
-----

Gadi.

[ reply ]
Re: "BIND 9 DNS Cache Poisoning" by Amit Klein (Trusteer) Jul 27 2007 07:19PM
Amit Klein (aksecurity gmail com) (1 replies)
Re: "BIND 9 DNS Cache Poisoning" by Amit Klein (Trusteer) Jul 27 2007 06:54PM
Tim Newsham (newsham lava net) (1 replies)
Re: "BIND 9 DNS Cache Poisoning" by Amit Klein (Trusteer) Jul 27 2007 10:34PM
Amit Klein (aksecurity gmail com)
Re: "BIND 9 DNS Cache Poisoning" by Amit Klein (Trusteer) Jul 27 2007 04:37PM
Tim (tim-security sentinelchicken org)
Re: "BIND 9 DNS Cache Poisoning" by Amit Klein (Trusteer) Jul 26 2007 10:50PM
Theo de Raadt (deraadt cvs openbsd org)
Re: "BIND 9 DNS Cache Poisoning" by Amit Klein (Trusteer) Jul 24 2007 08:07PM
Amit Klein (aksecurity gmail com)







 

Privacy Statement
Copyright 2009, SecurityFocus