Ostif.org Unbound DNS Audit Results – 1 Crit – 5 High – 5 Med
ostif.org
ostif.org
Genuine question: Which languages would you rather DNS servers/resolvers be written in?
Consequently, if you do not mind, which DNS server and resolver do you use?
[0] https://en.wikipedia.org/wiki/Unbound_(DNS_server)#History
You could always use Rust if bare-metal speed is important to you. But, as I'm sure tptacek will point out (and which I agree with), Go or Java or most other high-performance memory safe languages would be perfectly reasonable as well.
A lot of this boils down to using direct networking plumbing tricks and optimizing query handling into very fast flat memory lookups. A garbage collected language would be a terrible choice.
C is still the most common solution, but if I were writing a DNS server today, I'd go with rust.
Java - which others have suggested - definitely wouldn't work - no way you could make it anywhere near as tiny. Go is a bit better but you're still paying costs over C that add up if you're running hundreds of thousands of instances. Rust simply didn't exist when this was written. D? maaaybe, but then you just annihilated your pool of contributors. I'm not sure what the best choice would be, honestly.
https://github.com/NLnetLabs/unbound/commit/09845779d5f2c96e... Shell Injection in IPSECMOD
https://github.com/NLnetLabs/unbound/commit/b60c4a472c856f0a... Uninitialized Memory in worker_handle_request()
https://github.com/NLnetLabs/unbound/commit/f887552763477a60... Config Injection in create_unbound_ad_servers.sh
https://github.com/NLnetLabs/unbound/commit/226298bbd36f1f0f... Integer Overflow in Regional Allocator
https://github.com/NLnetLabs/unbound/commit/a3545867fcdec503... Integer Overflow in sldns_str2wire_dname_buf_origin()
https://github.com/NLnetLabs/unbound/commit/fa23ee8f31ba9a01... Out of Bounds Write in sldns_bget_token_par()
https://github.com/NLnetLabs/unbound/commit/f5e06689d193619c... Assert Causing DoS in synth_cname()
https://github.com/NLnetLabs/unbound/commit/d2eb78e871153f22... Assert Causing DoS in dname_pkt_copy()
https://github.com/NLnetLabs/unbound/commit/02080f6b180232f4... Integer Overflows in Size Calculations
https://github.com/NLnetLabs/unbound/commit/2d444a5037acff60... Insufficient Handling of Compressed Names in dname_pkt_copy()
https://github.com/NLnetLabs/unbound/commit/6c3a0b54ed8ace93... Out of Bound Write Compressed Names in rdata_copy()
Party like it’s 1975 indeed.