WARNING: AOL is hosed (again)

James Rishaw jamie at dilbert.ais.net
Fri Oct 16 20:11:28 UTC 1998


Mike Leber wrote:
> On Fri, 16 Oct 1998, Mark Borchers wrote:
> > Yep, somebody modified the delegation via a forged domain 
> > modification email.  An emergency root server update has been done to 
> > correct the problem.
> 
> Isn't an acknowlegement required with the correct tracking number?
> 
> If yes, were acknowlegement(s) also forged with guessed tracking numbers? 
> 
> If yes to my second question, then the tracking numbers either need to be
> made much longer and randomized or a one time pass phrase (session key) 
> needs to be added to the acknowlegement form. 

You can actually set a domain name so that it cannot be changed, by
any template, by any modification, correct guardian or NOT.

I would ass-u-me AOL did this, but obviously their DNS admins aren't
clued enough to figure this one out.

Tiem to hire people that know *all* of what they're supposed to do, not
just what they read out of an ORA book.

Gah.

-- 
jamie rishaw (efnet:gavroche)               American Information Systems, Inc.
                   Tel:312.425.7140, FAX:312.425.7240
                -- Your silence will NOT protect you. --
      "Did they just ask Don King to come to the lobby?!" - davidr



More information about the NANOG mailing list