Nginx DNS resolver vulnerabilities allow cache poisoning attack
blog.zorinaq.com
blog.zorinaq.com
DJB has been warning against non-randomized port numbers for DNS resolvers for more than 15 years.[1] This is not a new issue.
NGINX's response here is quite disheartening.
Nope! Still using ngx_random to generate packet IDs:
http://hg.nginx.org/nginx/file/tip/src/core/ngx_resolver.c#l...
And ngx_random is still #defined to random:
http://hg.nginx.org/nginx/file/tip/src/core/ngx_config.h#l57
I suggest updating your post to say that the issues are still unfixed as of today's date.
On a separate note; I'd love feedback on these areas of my code if anyone would care to... In TRust-DNS, at least to my best ability, I implemented them in these two locations:
randomized port (UDP only): https://github.com/bluejekyll/trust-dns/blob/master/client/s...
randomized msg id (TCP & UDP): https://github.com/bluejekyll/trust-dns/blob/master/client/s...
1. Switch off untrusted DNS (e.g. Google's) regardless of any POC. Nginx views using these as insecure (fair enough), so they may decline to issue security advisories for any exploit that doing so allows (less fair).
2. In certain circumstances (1) is insufficient; the post details at least some of these. But you need to do (1) regardless.
> Even pointing to a resolver on your internal local network may be a bad idea. Running a resolver on localhost is the only safe option.
In many cases, going to a localhost-only DNS is going to be way more complicated than getting off e.g. Google's open DNS, and thus conflating them likely means way more people giving up and sitting on untrusted DNS.