[Full-disclosure] DNS Smurf revisited

From: Ian Gulliver (ian-fulldisclosure_at_penguinhosting.net)
Date: 05/27/05

  • Next message: Martin Pitt: "[Full-disclosure] [USN-136-2] Fixed packages for USN-136-1"
    Date: Fri, 27 May 2005 10:28:37 -0400
    To: full-disclosure@lists.grok.org.uk
    
    
    
    
    

    DNS smurf is old news:

    http://www.s0ftpj.org/docs/spj-002-000.txt
    http://www.ciac.org/ciac/bulletins/j-063.shtml

    However, as ISPs continue to operate networks that let spoofed packets
    out this issue deserves a little publicity again.

    10:17:07.641061 IP (tos 0x0, ttl 64, id 46429, offset 0, flags [DF], length: 49) XXXXXXXXXXXXX.44295 > c.gtld-servers.net.domain: [udp sum ok] 18297 ANY? org. (21)
    10:17:07.673800 IP (tos 0x0, ttl 43, id 0, offset 0, flags [DF], length: 468) c.gtld-servers.net.domain > XXXXXXXXXXXXX.44295: 18297- 0/13/13 (440)

    % echo "2 k 468 49 / p" | dc
    9.55

    That's a 9.5X amplification of outgoing traffic; you can probably break
    10X with a little more work on the query and nameserver choices.

    SOLUTIONS
    ---------

    ISPs: Drop outgoing packets that don't originate from within your
    network. You should already be doing this, as it stops a variety of
    other attacks.

    NS operators: Ratelimit?

    Attached is a modernized proof of concept.

    -- 
    Ian Gulliver
    Penguin Hosting
    "Failure is not an option; it comes bundled with your Microsoft products."
    
    

    
    

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/




  • Next message: Martin Pitt: "[Full-disclosure] [USN-136-2] Fixed packages for USN-136-1"

    Relevant Pages

    • Re: [Full-disclosure] A Botted Fortune 500 a Day
      ... I believe security of an organisation is orthogonal to the number of ... >> Fortune 500 companies have more employees than some ISPs have customers. ... > compromises on their internal networks. ...
      (Bugtraq)
    • Re: [Full-disclosure] A Botted Fortune 500 a Day
      ... I believe security of an organisation is orthogonal to the number of ... Fortune 500 companies have more employees than some ISPs have customers. ... compromises on their internal networks. ... If one of your machines is spewing spam, ...
      (Full-Disclosure)
    • RE: Quickie... Hopefully!
      ... both ISPs feeds end up coming into a hub/switch ... route on the machine would be 1.1.1.1 and all traffic goes there. ... via the 1.1.1.1 gateway. ... addresses on the same NIC that are different networks. ...
      (freebsd-questions)
    • RE: Quickie... Hopefully!
      ... the interface two Ips with ifconfig and set the default route to our newest ... > via the 1.1.1.1 gateway. ... > addresses on the same NIC that are different networks. ... We are in the process of changing ISPs, ...
      (freebsd-questions)
    • Re: Orange ups prices
      ... individual or a group living in an apartment building that did this. ... know lots of people who believe in keeping their networks open, ... Installing an aerial to increase the range to a park and neighbours is likely to be classed as knowingly. ... in the minds of the ISPs - especially the cable companies which have a monopoly for cable within a geographic area - this is no different to stringing an ethernet cable between neighbours. ...
      (uk.telecom.mobile)