Great Circle Associates Firewalls
(January 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: dns spoofola
From: mjr @ tis . com
Date: Wed, 19 Jan 94 20:31:40 EST
To: firewalls @ GreatCircle . COM, hobbit @ wd40 . ftp . com

>Suppose someone intent on no good set a packet generator of some sort to firing
>lots of DNS replies with the responsible nameserver's source address and
>containing spoofed information, both PTR and A, at the target machine?  Chances
>seem good that the spoof DNS replies would get in there before the real reply
>just when the target machine tried to do the lookups, and then access would be
>granted to the spoofer's client address...

	It's fairly obvious and it's been done. This is one reason
we recommend not using DNS-based information for determining how
you will deal with a node. I.e., use IP addresses only.

	IP addresses are doubtless always going to be spoofable too,
but as you point out, it's pretty easy to spoof DNS by stuffing a
nameserver -- make 'em work for it. IP spoofing takes a higher
degree of expertise and access (I believe).

mjr.

Indexed By Date Previous: Re: dns spoofola
From: Darren Reed <avalon @ coombs . anu . edu . au>
Next: Questions about firewall examples
From: futoshi @ oho . sumikin . co . jp (futoshi miki)
Indexed By Thread Previous: Re: dns spoofola
From: John . MacFarlane @ Software . com (John L. MacFarlane) (by way of John . MacFarlane @ Software . com (John L. MacFarlane))
Next: Netblazer filter configuration
From: aem @ symbi1 . symbiosis . ahp . com (a.e.mossberg)

Google
 
Search Internet Search www.greatcircle.com