Re: djbdns/dnscache poisoning weakness

Matthew Dempsky <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Tue, Feb 10, 2009 at 2:27 PM, Dean Anderson <[email protected]> wrote:
> Admins might use caching nameservers to check SOAs.

Then they get the consequences of using a caching nameserver; i.e.,
the results might have been cached.

> All I can say is that if one does look at
> SOA's, one doesn't want to look at a _cached_ SOA, even if one uses a
> caching nameserver.

As much as I hate the idea of using BIND as an example, BIND caches
SOA records, and so I expect the majority of DNS software will have to
deal with the possibility of a caching nameserver caching SOA records.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.