nanog mailing list archives

Re: DOS attack against DNS?


From: Alon Tirosh <j0keralpha () gmail com>
Date: Tue, 17 Jan 2006 00:12:28 -0500

Not true,. the ANY query has mutliple uses for consolidating multiple
diagnostic queries into a single display, and also for diversion monitoring
systems on small domains or groups of same. Not all of us have the resources
(or time) of large ISPs behind us.

On 15 Jan 2006 17:27:40 +0000, Paul Vixie <vixie () vix com> wrote:


client xx.xx.xx.xx#6704: query: z.tn.co.za ANY ANY +E

class "ANY" has no purpose in the real world, not even for debugging.  if
you see it in a query, you can assume malicious intent.  if you hear it in
a query, you can safely ignore that query, or at best, map it to class
"IN".
--
Paul Vixie


Current thread: