Full Disclosure mailing list archives
RE: Re: Verisign abusing .COM/.NET monopoly, BIND releases new
From: "Rick Kingslan" <rkingsla () cox net>
Date: Wed, 17 Sep 2003 20:59:54 -0500
Folks, With total and complete respect for those offended by the morons at Verisign, or the merely amused - I really wish that I had your problems if this is the biggest bitch of the day.... I'll gladly trade. ;o> -rtk -----Original Message----- From: full-disclosure-admin () lists netsys com [mailto:full-disclosure-admin () lists netsys com] On Behalf Of Jose Nazario Sent: Wednesday, September 17, 2003 4:19 PM To: Thor Larholm Cc: list () dshield org; bugtraq () securityfocus com; NTBugtraq; full-disclosure () lists netsys com Subject: [Full-disclosure] Re: Verisign abusing .COM/.NET monopoly, BIND releases new a number of options exist to help you remedy this issue: - bind 9.2.3rc2 supports "delegation-only", stopping some wildcard implementations from making any difference if you simply want to stop traffic getting there (they are running a website and a partially functional MTA on that IP): - you can BGP null route this http://www.merit.edu/mail.archives/nanog/msg13715.html - cisco's NBAR functionality may be used to detect and block those reply packets from coming in by looking for the response from the nameservers. http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121newft/121 limit/121e/121e2/nbar2e.htm note that this wont stop the query from reaching verisign, it will just stop you from going to that IP. however, for some enforcing network privacy concerns, that may be worthwhile. hope this helps, ___________________________ jose nazario, ph.d. jose () monkey org http://monkey.org/~jose/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Re: Verisign abusing .COM/.NET monopoly, BIND releases new, (continued)
- Re: Verisign abusing .COM/.NET monopoly, BIND releases new Christopher Kruslicky (Sep 17)
- Re: Verisign abusing .COM/.NET monopoly, BIND releases new Jonathan A. Zdziarski (Sep 17)
- Re: Verisign abusing .COM/.NET monopoly, BIND releases new Jonathan A. Zdziarski (Sep 16)
- Re: Verisign abusing .COM/.NET monopoly, BIND releases new Michael D Schleif (Sep 17)
- Re: Verisign abusing .COM/.NET monopoly, BIND releases new Jose Nazario (Sep 17)
- Re: Verisign abusing .COM/.NET monopoly, BIND releases new D. Ian Miller (Sep 17)
- Re: Re: Verisign abusing .COM/.NET monopoly, BIND releases new Ron DuFresne (Sep 17)
- Re: Re: Verisign abusing .COM/.NET monopoly, BIND releases new Joshua Levitsky (Sep 17)
- Re: Re: Verisign abusing .COM/.NET monopoly, BIND releases new Jonathan A. Zdziarski (Sep 18)
- Re: Re: Verisign abusing .COM/.NET monopoly, BIND releases new Edward Rustin (Sep 18)
- Re: Verisign abusing .COM/.NET monopoly, BIND releases new D. Ian Miller (Sep 17)
- RE: Re: Verisign abusing .COM/.NET monopoly, BIND releases new Rick Kingslan (Sep 17)
- Re: Verisign abusing .COM/.NET monopoly, BIND releases new Nexus (Sep 17)
- Re: Verisign abusing .COM/.NET monopoly, BIND releases new Michael Renzmann (Sep 17)
- Verisign abusing .COM/.NET - nothing new.. Roelof Temmingh (Sep 17)
- RE: Verisign abusing .COM/.NET monopoly, BIND releases new Jonathan A. Zdziarski (Sep 17)
- Re: Verisign abusing .COM/.NET monopoly, BIND releases new Peter Busser (Sep 19)