Open Resolver Problems

Mikael Abrahamsson swmike at swm.pp.se
Mon Apr 1 15:51:01 UTC 2013


On Mon, 1 Apr 2013, Chris Boyd wrote:

> Just back to the office, and started checking my networks.  Found one of 
> the resolvers is a Netgear SOHO NAT box.  EoL'd, no new firmware 
> available.  Anyone have any feeling for what percentage are these types 
> of boxes?

If you buy "type of box" mean "small SOHO NAT router which does DNS 
resolving on the WAN interface" then I'd say "a lot". Someone does a 
rollout of new software and configuration and happens to mess up the 
config file (or the vendor just happens to enable global dns resolving in 
the new software) and this slips through testing, then you're there. I 
believe this happens all the time.

That's why the publication of these lists are important, in a lot of cases 
there are a lot of people who are simply not aware of these devices doing 
this, and they need to be poked to notice.

-- 
Mikael Abrahamsson    email: swmike at swm.pp.se




More information about the NANOG mailing list