Multiple DNS implementations vulnerable to cache poisoning

Jean-François Mezei jfmezei at vaxination.ca
Tue Jul 8 23:04:33 CDT 2008


Re: the tool

My DNS server does not serve the outside world. Incoming packets to port
53 are NAT directed to an non-existant IP on the LAN.

The tool uses my internet facing IP as my DNS server and tells me I am
vulnerable. Since, from the internet, connecting to that IP at port 53
will not get you to a DNS server, I find the tool's conclusion rather
without much value.






More information about the NANOG mailing list