nanog mailing list archives

RE: I've just tried new.net's plugin. Don't.


From: Roeland Meyer <rmeyer () mhsc com>
Date: Thu, 15 Mar 2001 15:40:13 -0800


DNS cache poisoning as adequately prevented by making your zone servers
non-recursive.

-----Original Message-----
From: Valdis.Kletnieks () vt edu [mailto:Valdis.Kletnieks () vt edu]
Sent: Thursday, March 15, 2001 2:03 PM
To: David Schwartz
Cc: nanog () merit edu
Subject: Re: I've just tried new.net's plugin. Don't. 



On Thu, 15 Mar 2001 11:59:28 PST, David Schwartz said:
    Did you know that you can choose which nameservers you 
use? And you can
continue to use the same nameservers no matter what 
provider you use.

Unless the ISP is security conscious and has allow-query and 
allow-recurse
ACLs for his netblocks only, to help combat DNS cache poisoning.

-- 
                              Valdis Kletnieks
                              Operating Systems Analyst
                              Virginia Tech






Current thread: