You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This is not a real security issue. For the “exploit” to work, as per the report, the attacker needs to control a nameserver Deadwood (MaraDNS) considers trustable; the attack starts off as “the malicious authoritative receives Deadwood's iterative query”
If an upstream server is controlled by an attacker, they can do a hell of a lot more than set QR=0. They can, for example, simply send Deadwood bogus replies.
This is a “they already got on the other side of the secure hatch” issue, not a real vector where one can poison Deadwood’s cache without controlling servers Deadwood considers authoritative.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Let me comment on this “security report”: GHSA-4jxw-xjwg-c754
This is not a real security issue. For the “exploit” to work, as per the report, the attacker needs to control a nameserver Deadwood (MaraDNS) considers trustable; the attack starts off as “the malicious authoritative receives Deadwood's iterative query”
If an upstream server is controlled by an attacker, they can do a hell of a lot more than set QR=0. They can, for example, simply send Deadwood bogus replies.
This is a “they already got on the other side of the secure hatch” issue, not a real vector where one can poison Deadwood’s cache without controlling servers Deadwood considers authoritative.
All reactions