Re: djbdns/dnscache poisoning weakness
Matthew Dempsky <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Tue, Feb 10, 2009 at 2:27 PM, Dean Anderson <[email protected]> wrote: > Admins might use caching nameservers to check SOAs. Then they get the consequences of using a caching nameserver; i.e., the results might have been cached. > All I can say is that if one does look at > SOA's, one doesn't want to look at a _cached_ SOA, even if one uses a > caching nameserver. As much as I hate the idea of using BIND as an example, BIND caches SOA records, and so I expect the majority of DNS software will have to deal with the possibility of a caching nameserver caching SOA records.