The cat is out of the bag - DNS spoofing details
amd.co.at
amd.co.at
http://www.kb.cert.org/vuls/id/800113
We use MaraDNS, and it was very comforting to see this on their blog:
http://maradns.blogspot.com/2008/07/maradns-is-immune-to-new...
</quote> http://www.matasano.com/log/1105/regarding-the-post-on-charg...
This is a good description of the attack.
"It also contained Additional RRs pointing WWW.VICTIM.COM to 6.6.6.0. Those records are in-bailiwick: Bob is in fact interested in VICTIM.COM for this query."
Why would it accept a record for www.victim.com for a query against aaaaa.victim.com, when www.victim.com isn't needed for that particular query?
Surely the fix is to further restrict fix 2: "The RR set poisoning attack is fixed by bailiwick checking, which is a quirky way of saying that resolvers simply remember that if they’re asking where WWW.VICTIM.COM is, they’re not interested in caching a new address for WWW.GOOGLE.COM in the same transaction."
Change that to say they are only interested in addresses that help them resolve the current query, and they will only use those intermediate addresses for the current query, and not globally.
Buuuut you'd have to consider that legitimate glue usage includes A records for NS records.