nanog mailing list archives
Re: Interesting new dns failures
From: Roger Marquis <marquis () roble com>
Date: Mon, 21 May 2007 11:26:31 -0700 (PDT)
On Mon, 21 May 2007, Chris L. Morrow wrote:
ok, so 'today' you can't think of a reason (nor can I really easily) but it's not clear that this may remain the case tomorrow.
Not a good justification for doing nothing while this sort of trojan propagates. As analogy, it is also true we cannot see how email-based trojans may be desirable tomorrow, but that doesn't stop us from protecting ourselves against their detrimental effects today.
It's possible that as a way to 'better loadshare' traffic akamai (just to make an example) could start doing this as well.
Actually not. There is no legitimate purpose for this dns hack.
So, I think that what we (security folks) want is probably not to auto-squish domains in the TLD because of NS's moving about at some rate other than 'normal'
Except that there's a lot more to this pattern than simply changing NS at a rate other than normal, enough that it can be easily identified for what it is. -- Roger Marquis Roble Systems Consulting http://www.roble.com/
Current thread:
- Re: Interesting new dns failures, (continued)
- Message not available
- Re: Interesting new dns failures Tim Franklin (May 21)
- Re: Interesting new dns failures Joe Abley (May 21)
- Re: Interesting new dns failures Simon Waters (May 21)
- RE: Interesting new dns failures michael.dillon (May 21)
- Re: Interesting new dns failures Stephane Bortzmeyer (May 21)
- Re: Interesting new dns failures Roger Marquis (May 21)
- Re: Interesting new dns failures Gadi Evron (May 21)
- Re: Interesting new dns failures Chris L. Morrow (May 21)
- Re: Interesting new dns failures Gadi Evron (May 21)
- Re: Interesting new dns failures Chris L. Morrow (May 21)
- Re: Interesting new dns failures Roger Marquis (May 21)
- Re: Interesting new dns failures Chris L. Morrow (May 21)
- Re: Interesting new dns failures Gadi Evron (May 21)
- Re: Interesting new dns failures Edward Lewis (May 21)
- Re: Interesting new dns failures Crist Clark (May 22)
- Re: Interesting new dns failures Paul Vixie (May 22)
- Re: Interesting new dns failures Gadi Evron (May 22)
- Re: Interesting new dns failures Chris L. Morrow (May 21)
- Re: Interesting new dns failures Gadi Evron (May 21)
- Re: Interesting new dns failures David Ulevitch (May 22)
- Re: Interesting new dns failures Gadi Evron (May 22)