Sunday, October 19. 2008Detecting DNS cache poisoningTrackbacks
Trackback specific URI for this entry
No Trackbacks
Comments
Display comments as
(Linear | Threaded)
The request for the non-existent host can be sourced from any IP. The caching server then goes through the recursive lookup, eventually asking the authoritative server for the answer. Here, destination IP is the authoritative server, destination port 53, and source IP is the caching server and source port 53 if you're really insecure or something (highly) random (if you're patched). This is where the attacker needs to start spoofing the authoritative answer. The ICMP backscatter will be caused by the attacker guessing the source port incorrectly and will be sent to the authoritative server because that is the address that has been spoofed.
|
Calendar
Momentary Wisdom"What I cannot create, I do not understand"
LinksCurrently Reading...Tags |
|||||||||||||||||||||||||||||||||||||||||||||||||