republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » ZyXEL » [z70] DoxPara port de-randomization / DNS cache poisoning?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
ADSL2+ router with WiFi and HomePlug »
« X-550 No - Wireless Connection  
AuthorAll Replies

jamesv
Premium
join:2003-03-08
Austin, TX

reply to dslpartner
Re: [z70] DoxPara port de-randomization / DNS cache poisoning?

The full report on this particular problem isn't public yet as we're still in the window to get it fixed. But enough credible people believe it's real (ISC, etc) I'm buying it until the full disclosure in a couple of weeks.

In the SPI case getting past it with UDP just means you need to correctly predict the port number a DNS query will come from next and blindly send a packet there. DNS queries have a 16-bit tag so that the query source can reject bogus replies but apparently that's not enough. And since the NAT makes the source port extremely predictable there's a problem...

The traffic is "valid" or it would be easy for the DNS query source to reject bogus replies. The traffic is forged and until DNSSEC is deployed all that can be done is to make this attack much harder by increasing the number of bits of randomness from 16-bits (the DNS packet tag) to, say, 31 bits (16 bits from the tag and 15 from the source port number).

ZyXel probably need not randomize the port: just add a short-circuit to the existing WAN port allocation code that says "if the LAN source port number is not allocated as a WAN source port, allocate it instead of using the clock-hand to find a new WAN port number" (in other words, don't remap port numbers unless there is actually a need to do so).

This approach is also unlikely to introduce new problems since one assumes the source ports numbers used by LAN hosts are reasonable to use on the WAN.

ZyXel needs to roll out firmware updates anyway to fix the internal DNS server since many people use that. Might as well fix port remapping at the same time.
-
Forums » Equipment Support » Hardware By Brand » ZyXELADSL2+ router with WiFi and HomePlug »
« X-550 No - Wireless Connection  


Friday, 21-Nov 04:20:41 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.
page compression OFF
Most commented news this week
· [198] Obama FCC Selection Team Won't Make AT&T Happy
· [102] DSL's Not Dead Yet
· [79] Zone Alarm Pro Free Just For Today
· [78] Harvard Law Professor Sues RIAA
· [67] New Xbox 360 'Experience' Goes Live
· [66] CRTC Rules Against Indie ISPs In Throttling Dispute
· [51] Cable Grabbing 71% Of New Broadband Customers
· [49] Storm Reviews Come Rolling In
· [48] Comcast DOCSIS 3.0 Hits Pacific Northwest In December
· [44] Comcast Offers 'Bare Bones' 768kbps VoIP Double Play
Most people now reading
· CRTC ruling coming Thursday Nov 20 [TekSavvy]
· Rocky - time to offer VPN service to all your customers [TekSavvy]
· Big Oil should bail out the Big 3, not us! [General Questions]
· [Config] Question about QoS Priority and Policing [Cisco]
· Service problems at multiple VoIP providers today? [VOIP Tech Chat]
· Extjs grid combo box. [Webmasters and Developers]
· Official news from TekSavvy regarding the CRTC descision [TekSavvy]
· Dumping Bell Home Phone Because Of CRTC ruling [TekSavvy]
· Pentagon Hit by Unprecedented Cyber Attack [Security]
· Very close to switching to Teksavvy but doubts [TekSavvy]