<rss version="2.0"><channel><title>Daily Dave (dailydave) Mailing List</title>
<link>http://seclists.org/#dailydave</link>
<description>This technical discussion list covers vulnerability research, exploit development, and security events/gossip.  It was started by ImmunitySec founder Dave Aitel and many security luminaries particpate.  Many posts simply advertise Immunity products, but you can&#39;t really fault Dave for being self-promotional on a list named DailyDave.</description>
<language>en-us</language><ttl>60</ttl>
<item><title>Re:  DNS Speculation</title><description>Posted by Cedric Blancher on Jul 24&lt;p&gt;


&lt;p&gt;
Le jeudi 24 juillet 2008 &agrave; 01:26 +0200, ninjaboy a &eacute;crit :
&lt;br /&gt;
&amp;gt; http://www.caughq.org/exploits/CAU-EX-2008-0002.txt
&lt;br /&gt;
&lt;p&gt;Not what I am talking about. Adding pwned.doxpara.com to a cache is fun,
&lt;br /&gt;
but not that interesting after all. I am talking about overwriting
&lt;br /&gt;
domain NS record into targeted cache....</description>
<link>http://seclists.org/dailydave/2008/q3/0116.html</link><guid isPermaLink="true">http://seclists.org/dailydave/2008/q3/0116.html</guid>
<pubDate>Thu, 24 Jul 2008 06:26:44 +0200</pubDate></item>
<item><title>Re:  Speculation</title><description>Posted by Alexander Sotirov on Jul 23&lt;p&gt;


&lt;p&gt;
On Tue, Jul 22, 2008 at 10:05:23PM -0400, dan_at_geer&amp;#46;org wrote:
&lt;br /&gt;
&amp;gt; mmaiffret_at_inveniosecurity&amp;#46;com writes
&lt;br /&gt;
&amp;gt; -+---------------------------------
&lt;br /&gt;
&amp;gt;  | Really it is a sad reminder that the current state of
&lt;br /&gt;
&amp;gt;  | the art when it comes to security and the resiliency
&lt;br /&gt;
&amp;gt;  | of...</description>
<link>http://seclists.org/dailydave/2008/q3/0115.html</link><guid isPermaLink="true">http://seclists.org/dailydave/2008/q3/0115.html</guid>
<pubDate>Wed, 23 Jul 2008 21:17:31 -0700</pubDate></item>
<item><title>Re:  DNS Speculation</title><description>Posted by ninjaboy on Jul 24&lt;p&gt;


&lt;p&gt;
2008/7/23 Cedric Blancher &amp;lt;blancher_at_cartel-securite&amp;#46;fr&amp;gt;:
&lt;br /&gt;
&amp;gt; Le mardi 22 juillet 2008 &agrave; 02:42 -0700, Alexander Sotirov a &eacute;crit :
&lt;br /&gt;
&amp;gt;&amp;gt; Spoofing a A record:
&lt;br /&gt;
&amp;gt;&amp;gt; Right before step 7, the attacker sends a spoofed response from ns.google.com
&lt;br /&gt;
&amp;gt;&amp;gt; that includes an A...</description>
<link>http://seclists.org/dailydave/2008/q3/0114.html</link><guid isPermaLink="true">http://seclists.org/dailydave/2008/q3/0114.html</guid>
<pubDate>Thu, 24 Jul 2008 01:26:19 +0200</pubDate></item>
<item><title>DNS Speculation</title><description>Posted by Joseph Patterson on Jul 23&lt;p&gt;


&lt;p&gt;
So, now I&#39;ve taken a good hard look at what someone claims is a mirror
&lt;br /&gt;
of a post that may or may not explain the whole DNS issue.  Based on
&lt;br /&gt;
that obviously perfectly reliable information, all I can say is &amp;quot;whee&amp;quot;.
&lt;br /&gt;
Actually, no, that&#39;s not all I can say.
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;
&lt;br /&gt;
&lt;p&gt;First off, DNS is...</description>
<link>http://seclists.org/dailydave/2008/q3/0113.html</link><guid isPermaLink="true">http://seclists.org/dailydave/2008/q3/0113.html</guid>
<pubDate>Wed, 23 Jul 2008 11:47:53 -0400</pubDate></item>
<item><title>Re:  DNS Speculation</title><description>Posted by Tyler Krpata on Jul 23&lt;p&gt;


&lt;p&gt;
On Tue, Jul 22, 2008 at 9:15 PM, Petja van der Lek &amp;lt;lek_at_xs4all&amp;#46;nl&amp;gt; wrote:
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; If it does, then this would obviously be an Extremely Bad thing, since
&lt;br /&gt;
&amp;gt; an attacker could just poison a resolver anytime, anyplace, anywhere. If
&lt;br /&gt;
&amp;gt; it doesn&#39;t overwrite the cached entry, I...</description>
<link>http://seclists.org/dailydave/2008/q3/0112.html</link><guid isPermaLink="true">http://seclists.org/dailydave/2008/q3/0112.html</guid>
<pubDate>Wed, 23 Jul 2008 11:08:58 -0400</pubDate></item>
<item><title>Re:  DNS Speculation</title><description>Posted by Cedric Blancher on Jul 23&lt;p&gt;


&lt;p&gt;
Le mardi 22 juillet 2008 &agrave; 02:42 -0700, Alexander Sotirov a &eacute;crit :
&lt;br /&gt;
&amp;gt; Spoofing a A record:
&lt;br /&gt;
&amp;gt; Right before step 7, the attacker sends a spoofed response from ns.google.com
&lt;br /&gt;
&amp;gt; that includes an A record for www.google.com and points it to 1.2.3.4 (which is
&lt;br /&gt;
&amp;gt; an attacker controlled...</description>
<link>http://seclists.org/dailydave/2008/q3/0111.html</link><guid isPermaLink="true">http://seclists.org/dailydave/2008/q3/0111.html</guid>
<pubDate>Wed, 23 Jul 2008 13:22:45 +0200</pubDate></item>
<item><title>Re:  DNS Speculation</title><description>Posted by Blue Boar on Jul 22&lt;p&gt;


&lt;p&gt;
Tetrapodal Giant wrote:
&lt;br /&gt;
&amp;gt; Since there really has been a fair amount of warning on this/these
&lt;br /&gt;
&amp;gt; issue(s), I&#39;m curious why it took so long to actually implement a fix.
&lt;br /&gt;
&lt;p&gt;Recall the earlier thread, about whether pen testers should have to 
&lt;br /&gt;
produce a working exploit, or whether the advisee...</description>
<link>http://seclists.org/dailydave/2008/q3/0110.html</link><guid isPermaLink="true">http://seclists.org/dailydave/2008/q3/0110.html</guid>
<pubDate>Tue, 22 Jul 2008 23:00:55 -0700</pubDate></item>
<item><title>Re:  DNS Speculation</title><description>Posted by Dominique Brezinski on Jul 22&lt;p&gt;


&lt;p&gt;
On Tue, Jul 22, 2008 at 10:27 AM, natron &amp;lt;shiftnato_at_gmail&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&amp;gt; I assume that mucking with ns.google.com&#39;s ability to update
&lt;br /&gt;
&amp;gt; *.google.com records on the fly would probably negatively impact large
&lt;br /&gt;
&amp;gt; organizations current DNS architectures, where they probably...</description>
<link>http://seclists.org/dailydave/2008/q3/0109.html</link><guid isPermaLink="true">http://seclists.org/dailydave/2008/q3/0109.html</guid>
<pubDate>Tue, 22 Jul 2008 19:22:46 -0700</pubDate></item>
<item><title>Re:  Speculation</title><description>Posted by dan_at_geer.org on Jul 22&lt;p&gt;


&lt;p&gt;
mmaiffret_at_inveniosecurity&amp;#46;com writes
&lt;br /&gt;
-+---------------------------------
&lt;br /&gt;
&amp;nbsp;| Really it is a sad reminder that the current state of
&lt;br /&gt;
&amp;nbsp;| the art when it comes to security and the resiliency
&lt;br /&gt;
&amp;nbsp;| of our systems has a lot to do with making sure the
&lt;br /&gt;
&amp;nbsp;| good guys only talk...</description>
<link>http://seclists.org/dailydave/2008/q3/0108.html</link><guid isPermaLink="true">http://seclists.org/dailydave/2008/q3/0108.html</guid>
<pubDate>Tue, 22 Jul 2008 22:05:23 -0400</pubDate></item>
<item><title>Re:  DNS Speculation</title><description>Posted by Petja van der Lek on Jul 23&lt;p&gt;


&lt;p&gt;
&lt;p&gt;In an effort to move beyond the &amp;quot;guess the bug&amp;quot; stage a bit, and
&lt;br /&gt;
thinking more about detection and mitigation, I&#39;m trying to gauge
&lt;br /&gt;
whether this vulnerability is Really Bad&trade; or Extremely Bad&trade;. In
&lt;br /&gt;
particular, whether ye olde caching resolver will overwrite an RR
&lt;br /&gt;
already in the cache...</description>
<link>http://seclists.org/dailydave/2008/q3/0107.html</link><guid isPermaLink="true">http://seclists.org/dailydave/2008/q3/0107.html</guid>
<pubDate>Wed, 23 Jul 2008 03:15:58 +0200</pubDate></item>
<item><title>Re:  DNS Speculation</title><description>Posted by Tetrapodal Giant on Jul 22&lt;p&gt;


&lt;p&gt;
Hi All -
&lt;br /&gt;
&lt;p&gt;On 7/22/08, Parity &amp;lt;pty.err_at_gmail&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&lt;p&gt;&amp;gt; &amp;gt;From DJB&#39;s notes:
&lt;br /&gt;
&lt;p&gt;I&#39;m a huge nobody at this smarty party, but I&#39;m bothered by a few
&lt;br /&gt;
aspects of this whole issue.
&lt;br /&gt;
&lt;p&gt;Since there really has been a fair amount of warning on this/these
&lt;br /&gt;
issue(s), I&#39;m curious why it took...</description>
<link>http://seclists.org/dailydave/2008/q3/0106.html</link><guid isPermaLink="true">http://seclists.org/dailydave/2008/q3/0106.html</guid>
<pubDate>Tue, 22 Jul 2008 14:52:56 -0500</pubDate></item>
<item><title>Re:  DNS Speculation</title><description>Posted by Tyler Krpata on Jul 22&lt;p&gt;


&lt;p&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; I&#39;ve been trying to understand the attack, but I am not sure that I really get
&lt;br /&gt;
&amp;gt; it. It looks like the only way it would work is if the DNS resolvers accept
&lt;br /&gt;
&amp;gt; records they didn&#39;t ask for. Do they? If they do, why?
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&lt;p&gt;They do, for &amp;quot;in-bailiwick&amp;quot; records.
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/dailydave/2008/q3/0105.html</link><guid isPermaLink="true">http://seclists.org/dailydave/2008/q3/0105.html</guid>
<pubDate>Tue, 22 Jul 2008 13:54:29 -0400</pubDate></item>
<item><title>Re:  DNS Speculation</title><description>Posted by natron on Jul 22&lt;p&gt;


&lt;p&gt;
Additionally, there&#39;s no A record in the invalid response, but there
&lt;br /&gt;
are A records if it&#39;s a valid response.  Consider the output from
&lt;br /&gt;
www.google.com:
&lt;br /&gt;
&lt;p&gt;;; AUTHORITY SECTION:
&lt;br /&gt;
l.google.com.           56129   IN      NS      e.l.google.com.
&lt;br /&gt;
l.google.com.           56129   IN      NS...</description>
<link>http://seclists.org/dailydave/2008/q3/0104.html</link><guid isPermaLink="true">http://seclists.org/dailydave/2008/q3/0104.html</guid>
<pubDate>Tue, 22 Jul 2008 12:27:09 -0500</pubDate></item>
<item><title>Re:  DNS Speculation</title><description>Posted by natron on Jul 22&lt;p&gt;


&lt;p&gt;
In your scenario, the root servers would have more control over the
&lt;br /&gt;
*.google.com domain than google.com would, correct?  You are proposing
&lt;br /&gt;
that the client/resolving DNS server cache the root server&#39;s response
&lt;br /&gt;
and not let ns.google.com overwrite the entry.  As a general
&lt;br /&gt;
discussion of trust, it...</description>
<link>http://seclists.org/dailydave/2008/q3/0103.html</link><guid isPermaLink="true">http://seclists.org/dailydave/2008/q3/0103.html</guid>
<pubDate>Tue, 22 Jul 2008 12:18:12 -0500</pubDate></item>
<item><title>Re:  DNS Speculation</title><description>Posted by Dominique Brezinski on Jul 22&lt;p&gt;


&lt;p&gt;
On Tue, Jul 22, 2008 at 9:55 AM, Alexander Sotirov &amp;lt;alex_at_sotirov&amp;#46;net&amp;gt; wrote:
&lt;br /&gt;
&amp;gt; Alright, so then my question is why would the resolver accept the additional RR
&lt;br /&gt;
&amp;gt; record for ns.google.com? It didn&#39;t ask for ns.google.com, it should just ignore
&lt;br /&gt;
&amp;gt; the extra RR. The only...</description>
<link>http://seclists.org/dailydave/2008/q3/0102.html</link><guid isPermaLink="true">http://seclists.org/dailydave/2008/q3/0102.html</guid>
<pubDate>Tue, 22 Jul 2008 10:17:35 -0700</pubDate></item>
</channel></rss>