I've just tried new.net's plugin. Don't.

Roeland Meyer rmeyer at mhsc.com
Thu Mar 15 23:40:13 UTC 2001


DNS cache poisoning as adequately prevented by making your zone servers
non-recursive.

> -----Original Message-----
> From: Valdis.Kletnieks at vt.edu [mailto:Valdis.Kletnieks at vt.edu]
> Sent: Thursday, March 15, 2001 2:03 PM
> To: David Schwartz
> Cc: nanog at merit.edu
> Subject: Re: I've just tried new.net's plugin. Don't. 
> 
> 
> 
> On Thu, 15 Mar 2001 11:59:28 PST, David Schwartz said:
> > 	Did you know that you can choose which nameservers you 
> use? And you can
> > continue to use the same nameservers no matter what 
> provider you use.
> 
> Unless the ISP is security conscious and has allow-query and 
> allow-recurse
> ACLs for his netblocks only, to help combat DNS cache poisoning.
> 
> -- 
> 				Valdis Kletnieks
> 				Operating Systems Analyst
> 				Virginia Tech
> 
> 




More information about the NANOG mailing list