Open Resolver Problems

Scott Noel-Hemming frogstarr78 at gmail.com
Sat Mar 30 03:55:55 UTC 2013


On 03/25/2013 08:44 AM, Valdis.Kletnieks at vt.edu wrote:
> On Mon, 25 Mar 2013 15:38:01 -0000, Nick Hilliard said:
>> On 25/03/2013 14:33, Mikael Abrahamsson wrote:
>>> I would like to be able to request an IP list of open resolvers in my ASN,
>>> perhaps sent to the contact details in RIPE whois database to make sure I'm
>>> not falsely representing that ASN.
>> Why would that matter?  This is publicly available information.
> Some of us have both publicly-facing authoritative DNS, and inward
> facing recursive servers that may be open resolvers but can't be
> found via NS entries (so the IP addresses of those aren't exactly
> publicly available info).
Sounds like your making the faulty assumption that an attacker would use 
normal means to find your servers.

-- 
()  ascii ribbon campaign - against html e-mail
/\  www.asciiribbon.org   - against proprietary attachments





More information about the NANOG mailing list