[Bug 247409] Re: Python-dns does not randomize TID causing DNS poisoning risk

Scott Kitterman ubuntu at kitterman.com
Fri Jul 11 19:15:43 UTC 2008


Confirmed on Gutsy (if I'm reading the tcpdump output correctly):

15:08:07.642049 IP vood.lan.domain > sebner-desktop.local.32772: 0 5/7/3 CNAME www.l.google.com.,[|domain]
15:08:07.646050 IP 192.168.128.2.domain > sebner-desktop.local.32773: 30850- 1/0/0 PTR[|domain]
15:08:08.262120 IP sebner-desktop.local.32773 > vood.lan.domain: 0+ A? www.google.com. (32)
15:08:08.270121 IP vood.lan.domain > sebner-desktop.local.32773: 0 5/7/3 CNAME www.l.google.com.,[|domain]
15:08:08.690169 IP sebner-desktop.local.32773 > vood.lan.domain: 0+ A? www.google.com. (32)
15:08:08.690169 IP vood.lan.domain > sebner-desktop.local.32773: 0 5/7/3 CNAME www.l.google.com.,[|domain]
15:08:09.082213 IP sebner-desktop.local.32773 > vood.lan.domain: 0+ A? www.google.com. (32)
15:08:09.082213 IP vood.lan.domain > sebner-desktop.local.32773: 0 5/7/3 CNAME www.l.google.com.,[|domain]
15:08:09.526264 IP sebner-desktop.local.32773 > vood.lan.domain: 0+ A? www.google.com. (32)
15:08:09.534265 IP vood.lan.domain > sebner-desktop.local.32773: 0 5/7/3 CNAME www.l.google.com.,[|domain]

** Changed in: linux-source-2.6.20 (Ubuntu Feisty)
   Importance: Undecided => High
       Status: New => Confirmed

** Changed in: linux-source-2.6.22 (Ubuntu Gutsy)
   Importance: Undecided => High
       Status: New => Confirmed

-- 
Python-dns does not randomize TID causing DNS poisoning risk
https://bugs.launchpad.net/bugs/247409
You received this bug notification because you are a member of Kernel
Bugs, which is subscribed to linux-source-2.6.15 in ubuntu.




More information about the kernel-bugs mailing list