On Jul 9, 2008, at 12:19 PM, Ted Unangst wrote:
>> n front). something like,
But does it allow a poisoned reply from the spoofed address?
As I understand the threat, based on the limited information:
1. Attacker sends valid user a www.badman.com link to click on
2. Resolver queries to badman.com NS from port 55555 for
www.badman.com, which is a CNAME to www.ebay.com
3. New query for www.ebay.com to ebay.com NS originates from udp port
54321
4. A spoofed UDP packet from the badman.com NS using 55555 shouldn't
match the ebay query, and the poisoning shouldn't work.
If I'm missing something, I welcome any corrections.
Thanks,
Steve
| Greg KH | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
| Andrew Morton | Re: 2.6.23-rc6-mm1 |
| Luciano Rocha | usb hdd problems with 2.6.27.2 |
git: | |
| Gerrit Renker | [PATCH 15/37] dccp: Set per-connection CCIDs via socket options |
| Andrew Morton | Re: [BUG] New Kernel Bugs |
| David Miller | [GIT]: Networking |
| Jarek Poplawski | [PATCH take 2] pkt_sched: Protect gen estimators under est_lock. |
