Re: [bugtraq] Re: [Full-disclosure] CAU-EX-2008-0002: Kaminsky DNS Cache Poisoning




On FreeBSD 7.0-STABLE (updated on Fri May 23) it fails to create raw
socket even when running as root:
...
[-] This module is configured to use a raw IP socket. On Unix systems,
only the root user is allowed to create raw sockets.Please run the
framework as root to use this module.

[*] Attempting to inject poison records for example.com.'s nameservers
into 202.72.241.4:55088...
[-] Auxiliary failed: undefined method `sendto' for nil:NilClass

Thats a known issue. May be on any *BSD system, not sure
about Windows. The authors were alerted, but don't have a time to
resolution set. I guess Linux is the default of the hack platform. ;)

Tuc/TBOH



Relevant Pages

  • Re[2]: accounting with ipfw (gid, uid riles)
    ... MS> The uid associated with a socket is the uid of the process which created ... it's still accounted to root. ... far, is adding alias interface, bind squid to this interface and count ...
    (FreeBSD-Security)
  • Re: [Full-disclosure] [bugtraq] Re: CAU-EX-2008-0002: Kaminsky DNS Cache Poisoning
    ... This module is configured to use a raw IP socket. ... only the root user is allowed to create raw sockets.Please run the ...
    (Full-Disclosure)
  • Re: Recent bad dental experience
    ... Root fragments are left behind on occasion and healing will ... During the extraction the dentist said the tooth broke up into many ... index finger to feel if there was any food material in the socket. ... my surprise, I felt a small, hard, loose fragment, which I was able to ...
    (sci.med.dentistry)
  • Re[2]: accounting with ipfw (gid, uid riles)
    ... But I wanted to count Squid traffic. ... If squid runs the listen as root, all sockets created from that listen ... socket will also be accounted to root. ... not know how natd would affect connections in terms of uid accounting. ...
    (FreeBSD-Security)
  • Re: How to delete unix socket entries
    ... > respond to incoming connections, so that after the socket was opened, the ... root screen 30084 4 stream /tmp/screens/S-paul/30084.ttyp0.hannibal ... root pure-ftp 22112 3 dgram syslogd:3 ...
    (freebsd-hackers)