Re: [Full-disclosure] DNS spoofing issue. Thoughts on potential exploits

2008-07-24 Thread Troy Xyz
I am now posting some analysis I wrote on the subject right after my last post. Since the exploits are now available too, this should primarily be helpful to the good guys. I wrote this without full details of the exploit, but it shoud all be pertinent nonetheless. It might help in some cases where

[Full-disclosure] DNS spoofing issue. Thoughts on potential exploits

2008-07-17 Thread Troy Xyz
Hi, I am troubled by these kinds of solutions which only help administrators with standard distributions. Any kind of deviation from the norm, and it will be impossible to fix one's servers, or assess possible vulnerabilities. I wanted to understand how someone could exploit this flaw against sys