Darren Reed
2007-11-05 21:37:01 UTC
Moving this to tech-net...
Queries for non-existant names returns an A record that points
to one of their web servers saying "welcome"?
Do they do it when recursion is both enabled and disabled?
Darren
--
Posted automagically by a mail2news gateway at muc.de e.V.
Please direct questions, flames, donations, etc. to news-***@muc.de
How do we feel about a mod to the resolver library to implement a DNS
blacklist? Verizon and others are starting to resurrect sitefinder on
a local basis. It occurs to me that one self-defense mechanism would
be the ability to add a line to /etc/resolv.conf that declares certain
IP addresses as evil^H^H^H^Hinaccurate and treat responses with those
addresses as returning NXDOMAIN. This would allow users behind those
hijacking DNS servers to identify and redirect the redirection.
What exactly is the problem?blacklist? Verizon and others are starting to resurrect sitefinder on
a local basis. It occurs to me that one self-defense mechanism would
be the ability to add a line to /etc/resolv.conf that declares certain
IP addresses as evil^H^H^H^Hinaccurate and treat responses with those
addresses as returning NXDOMAIN. This would allow users behind those
hijacking DNS servers to identify and redirect the redirection.
Queries for non-existant names returns an A record that points
to one of their web servers saying "welcome"?
Do they do it when recursion is both enabled and disabled?
Darren
--
Posted automagically by a mail2news gateway at muc.de e.V.
Please direct questions, flames, donations, etc. to news-***@muc.de