Updating Security Considerations in RFC 6762
Loganaden Velvindron <[email protected]> Tue, 7 Apr 2015 05:25:15 +0000
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <CAOp4FwS6LkuqOpUNFzzbLZS7X5=xKt_HTwcMWvQWR2ovUn8ftQ@mail.gmail.com> |
Dear All, Following the release of a security vulnerability by CERT: https://www.kb.cert.org/vuls/id/550620 It might be worth considering updating RFC 6762 to advise implementors against amplification attacks by rate-limiting responses or refusing to reply to queries from outside local link. Quote: "Impact An mDNS response to a unicast query originating outside of the local link network may result in information disclosure, such as disclosing the device type/model that responds to the request or the operating system running such software. The mDNS response may also be used to amplify denial of service attacks against other networks." Feedback welcomed. //Logan C-x-C-c -- This message is strictly personal and the opinions expressed do not represent those of my employers, either past or present. _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext