RE: Disman WG last call ondraft-ietf-disman-remops-mib-v2-02.txt

Juergen Quittek <[email protected]>
Newsgroups gmane.ietf.disman
Message-ID <[email protected]>
Dan,

Thanks for the comment.  I will fix this.

    Juergen
-- 
Juergen Quittek        [email protected]       Tel: +49 6221 90511-15
NEC Europe Ltd.,       Network Laboratories        Fax: +49 6221 90511-55
Kurfuersten-Anlage 36, 69115 Heidelberg, Germany   http://www.netlab.nec.de


--On 09.07.2004 19:56 h +0300 Romascanu, Dan (Dan) wrote:

> Randy,
>
> I buy your argument. However, in this case, the text preceding this recommendation in the paragraph should also detail the threats of the DNS lookups. Right now it refers only to pings and traceroutes hazards.
>
>>    In general, both the ping and traceroute functions when used
>>    excessively are considered a form of system attack.  In the case of
>>    ping sending a system requests too often can negatively effect its
>>    performance or attempting to connect to what is supposed to be an
>>    unused port can be very unpredictable.  Excessive use of the
>>    traceroute capability can like ping negatively affect system
>>    performance.  In insecure environments it is RECOMMENDED that the
>>    MIBs defined within this memo not be supported.
>>
>
> Regards,
>
> Dan
>
>
>
>> >
>>
>> > It looks fine with one observation. The phrase:
>> >
>> >  In insecure environments it is RECOMMENDED that the
>> >    MIBs defined within this memo not be supported.
>> >
>> > seems intended to apply only for the ping and traceroute
>> MIB, not for the lookup MIB.
>>
>> (As technical contributor)
>> I disagree.  One could use excessive DNS lookups as a form of
>> DoS attack.
>> Consequently, I think the lookup MIB merits the same level of
>> protection as
>> the traceroute MIB.
>>
>> > In any case, this seems redundant with the generic recommendations
>> > that are part of the security boilerplate which say:
>> ...
>>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.