nanog mailing list archives
Re: maybe a dumb idea on how to fix the dns problems i don't know....
From: Joe Abley <jabley () ca afilias info>
Date: Sat, 9 Aug 2008 18:15:56 -0400
On 9 Aug 2008, at 18:10, Matt F wrote:
Why not just require TCP for a lookup if a response with an incorrect TXID is received? You could require TCP for just the one lookup or for some configured interval, say 1 hour. That should slow attackers down substantially.
That sounds like a good way for a remote attacker to make a resolver disable UDP transport for a server, more or less at will. I'm not sure I like the sound of that.
Joe
Current thread:
- maybe a dumb idea on how to fix the dns problems i don't know.... Chris Paul (Aug 09)
- RE: maybe a dumb idea on how to fix the dns problems i don't know.... Church, Charles (Aug 09)
- Re: maybe a dumb idea on how to fix the dns problems i don't know.... Joe Abley (Aug 09)
- Re: maybe a dumb idea on how to fix the dns problems i don't know.... Matt F (Aug 09)
- Re: maybe a dumb idea on how to fix the dns problems i don't know.... Joe Abley (Aug 09)
- Re: maybe a dumb idea on how to fix the dns problems i don't know.... Paul Vixie (Aug 09)
- Re: maybe a dumb idea on how to fix the dns problems i don't know.... Randy Bush (Aug 09)
- Re: maybe a dumb idea on how to fix the dns problems i don't know.... Michael Thomas (Aug 09)
- Re: maybe a dumb idea on how to fix the dns problems i don't know.... Chris Paul (Aug 09)
- Re: maybe a dumb idea on how to fix the dns problems i don't know.... brett watson (Aug 09)
- Re: maybe a dumb idea on how to fix the dns problems i don't know.... Paul Vixie (Aug 09)
- Re: maybe a dumb idea on how to fix the dns problems i don't know.... Joe Abley (Aug 10)
- Re: maybe a dumb idea on how to fix the dns problems i don't know.... Paul Vixie (Aug 10)
- Re: maybe a dumb idea on how to fix the dns problems i don't know.... Joe Abley (Aug 10)
- Re: maybe a dumb idea on how to fix the dns problems i don't know.... Paul Vixie (Aug 10)
- Re: maybe a dumb idea on how to fix the dns problems i don't know.... Joe Abley (Aug 09)
- RE: maybe a dumb idea on how to fix the dns problems i don't know.... Church, Charles (Aug 09)