DNS deluge for x.p.ctrc.cc

Chris Adams cmadams at hiwaay.net
Sat Feb 25 00:58:12 UTC 2006


Once upon a time, Rob Thomas <robt at cymru.com> said:
> Limit recursion to trusted netblocks and customers.  Do not permit
> your name servers to provide recursion for the world.  If you do,
> you will contribute to one of these attacks.

One thing to note: we've discovered that on some common DSL routers, the
internal DNS caching server is on by default and answers requests on the
outside IP address.  IIRC some even do it when configured for NAT.

So, even when you disable outside recursion, things you may not think of
on the inside of your network may still allow outside DNS recursion.

-- 
Chris Adams <cmadams at hiwaay.net>
Systems and Network Administrator - HiWAAY Internet Services
I don't speak for anybody but myself - that's enough trouble.



More information about the NANOG mailing list