DNS: Definitely Not Safe?

MARLON BORBA MBORBA at trf3.gov.br
Wed Feb 14 18:22:44 UTC 2007


mea culpa, mea maxima culpa :-(
my intention, when suggested that reading, was to get your attention about that recent attack which targeted DNS top-level servers and to listen your opinions.
i promise not to post porn, ops, FUD material to nanog again.



Abraços,

Marlon Borba, CISSP, DataCenter Associate
Técnico Judiciário - Segurança da Informação
TRF 3ª Região
(11) 3012-1683
--
1997-2007 - Dez Anos da DSUP.
Conhecimento Gerando Soluções.
--

>>> Paul Vixie <vixie at vix.com> 14/2/2007 15:01:09 >>>

bortzmeyer at nic.fr (Stephane Bortzmeyer) writes:

> It may be on-topic but it is full of FUD, mistakes and blatant
> b...t. Certainly not the recommended reading for the sysadmin.

i think you're being way to kind here.

> The best stupid sentence is the one asking firewalls in front of the
> DNS servers... to prevent tunneling data over DNS!

just as the most common lie told by spammers is "dear friend", so it is
that the biggest error in this piece is in the first sentence:

	When it comes to the Web's domain name system (DNS),

this guy was probably writing netware-vs-smb comparisons during the two
decades that the internet existed before the web came along.  the web is
an internet application, and the dns is part of the internet, not part of
the web.  the rest of the article is equally horrific in its maltreatment
and ignorance of facts.
-- 
Paul Vixie




More information about the NANOG mailing list