Open Resolver Problems

joel jaeggli joelja at bogus.com
Mon Apr 1 19:40:57 UTC 2013


On 4/1/13 11:59 AM, Valdis.Kletnieks at vt.edu wrote:
> On Mon, 01 Apr 2013 19:40:03 +0100, Tony Finch said:
>
>> You should be able to get a reasonable sample of IPv6 resolvers from the query
>> logs of a popular authoritative server.
> Hopefully, said logs are not easily accessible to the miscreants.
Miscreants with popular zones clearly can do that.

Reverse-lookups for spam originating machines might for example be a 
sufficient source of queries if you control the reverse zone.

The DNS makes it's own gravy.
> (I still expect the most feasible method for the miscreants is to start a
> botnet and see what boxes get handed an IPv6 DNS via dhcp6).





More information about the NANOG mailing list