Re: djbdns/dnscache poisoning weakness
[email protected] (Paul Jarc)
| Newsgroups | gmane.network.djbdns |
|---|---|
| Organization | What did you have in mind? A short, blunt, human pyramid? |
| Message-ID | <[email protected]> |
Michael Sierchio <[email protected]> wrote: > Paul Jarc wrote: >> ... An attacker can send an SOA >> query ... > > Really? I think it's important to be explicit about what > the threat model is. Attackers don't make queries to your > dnscache, presumably. One of the examples given previously was a large ISP, with many customers sharing a cache. One customer may try to poison the cache to exploit the other customers. paul