| To: | djbdns Mailing List <dns@list.cr.yp.to> |
|---|---|
| Subject: | Re: djbdns-1.05-epoll + speedup patch |
| From: | Charles Cazabon <dns@discworld.dyndns.org> |
| Date: | Wed, 7 Mar 2007 09:57:55 -0600 |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | gmail-djbdns@securepoint.com |
| Delivered-to: | sp.com.list@gmail.com |
| Delivered-to: | mailing list dns@list.cr.yp.to |
| In-reply-to: | <20070307153920.e4674dxjvrwf6nm4@m.safari.iki.fi> |
| Mail-followup-to: | djbdns Mailing List <dns@list.cr.yp.to> |
| Mailing-list: | contact dns-help@list.cr.yp.to; run by ezmlm |
| References: | <20070116171333.GA5674@m.safari.iki.fi> <20070222122129.GE3982@m.safari.iki.fi> <20070222162522.GG3982@m.safari.iki.fi> <20070304161657.qrytvzoi37inmj45@m.safari.iki.fi> <20070307143501.GA19509@codeblau.de> <20070307153920.e4674dxjvrwf6nm4@m.safari.iki.fi> |
| User-agent: | Mutt/1.5.11 |
Sami Farin <safari-dns@safari.iki.fi> wrote: > > > > surf is there for security reasons. It is MEANT to take some time. > > That's where its security comes from. > > Well BIND seems to do better, according to this. > http://www.lurhq.com/cachepoisoning.html Eh? Are you referring to that analysis of the PRNG in dnscache? The calprob output shows the randomness is still not perfect (in fact, it is slightly worse than BIND 9; 30% probability of a successful guess with a spoofing set size of 5000): [...] This is however offset by the fact that djbdns also generates random numbers for the source port of each query, [...] This forces the attacker to guess transaction ID and source port simultaneously. It is immensely difficult to succeed at such an attack, dnscache is harder to poison than BIND 8 or BIND 9. Charles -- ----------------------------------------------------------------------- Charles Cazabon <dns@discworld.dyndns.org> GPL'ed software available at: http://pyropus.ca/software/ ----------------------------------------------------------------------- |
| Previous by Date: | Re: djbdns-1.05-epoll + speedup patch, Emilio Perea |
|---|---|
| Next by Date: | Re: djbdns-1.05-epoll + speedup patch, Sami Farin |
| Previous by Thread: | Re: djbdns-1.05-epoll + speedup patch, Emilio Perea |
| Next by Thread: | Re: djbdns-1.05-epoll + speedup patch, Sami Farin |
| Indexes: | [Date] [Thread] [Top] [All Lists] |