nanog mailing list archives

Re: DNS Amplification Attacks


From: Michael.Dillon () btradianz com
Date: Thu, 23 Mar 2006 09:35:34 +0000


DNS looking glasses, in much the same way that we use web-form based
BGP or traceroute looking glasses today.

Open resolvers are far better then looking glasses to assess the state
of DNS, and we are campaigning against them.  You can't have it both
ways. 8-(

What is the definition of "DNS Looking Glass"?
If it is a PERL CGI script then I would agree with you.
If it is a DNS proxy that applies rate limiting
and damping then I disagree with you. 

--Michael Dillon


Current thread: