nanog mailing list archives

Re: DNS cache poisoning attacks -- are they real?


From: Randy Bush <randy () psg com>
Date: Sun, 27 Mar 2005 22:11:54 -0800


And to Randy's point about problems with open recursive nameservers... 
abusers have been known to cache "hijack".  Register a domain, 
configure an authority with very large TTLs, seed it onto known open 
recursive nameservers, update domain record to point to the open 
recursive servers rather than their own.  Wammo, "bullet proof" dns 
hosting.

as has been said here repeatedly, you should not be running servers,
recursive or not, on old broken and vulnerable software.

randy


Current thread: