RE: Disman WG last call ondraft-ietf-disman-remops-mib-v2-02.txt
"Romascanu, Dan (Dan)" <[email protected]>
| Newsgroups | gmane.ietf.disman |
|---|---|
| Message-ID | <AAB4B3D3CF0F454F98272CBE187FDE2F056B3187@is0004avexu1.global.avaya.com> |
Randy, I buy your argument. However, in this case, the text preceding this recommendation in the paragraph should also detail the threats of the DNS lookups. Right now it refers only to pings and traceroutes hazards. > In general, both the ping and traceroute functions when used > excessively are considered a form of system attack. In the case of > ping sending a system requests too often can negatively effect its > performance or attempting to connect to what is supposed to be an > unused port can be very unpredictable. Excessive use of the > traceroute capability can like ping negatively affect system > performance. In insecure environments it is RECOMMENDED that the > MIBs defined within this memo not be supported. > Regards, Dan > > > > > It looks fine with one observation. The phrase: > > > > In insecure environments it is RECOMMENDED that the > > MIBs defined within this memo not be supported. > > > > seems intended to apply only for the ping and traceroute > MIB, not for the lookup MIB. > > (As technical contributor) > I disagree. One could use excessive DNS lookups as a form of > DoS attack. > Consequently, I think the lookup MIB merits the same level of > protection as > the traceroute MIB. > > > In any case, this seems redundant with the generic recommendations > > that are part of the security boilerplate which say: > ... >