Re: .dk-TLD-problems

Andy Bradford <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
Thus said Tommy Mogensen on Wed, 09 Sep 2009 20:41:49 +0200:

> Since Aug.  30th redelegation has  included 'check for  handeling lame
> delegations'.  This entails  asking for  a  RR that  is definetly  not
> hosted on the authoritative nameserver  you want to redelegate to, and
> expecting an NXDOMAIN answer. If  the new authoritative nameservers do
> not answer and  the client has to timeout,  the redelegation procedure
> fails (output below),  thus it is AFAIK not possible  to redelegate to
> namesevers running tinydns at all.

I particularly like this behavior. I  have seen a lot of ``backscatter''
attacks  that target  some  other system  by querying  my  server for  .
records,  however,  due to  tinydns'  design,  my  DNS server  does  not
participate. You might want to  inform DK-Hostmaster that by making this
a requirement they are helping provide attack vectors for DoS authors.

Andy
-- 
[-----------[system uptime]--------------------------------------------]
  9:08pm  up 9 min,  1 user,  load average: 1.07, 1.08, 0.64
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.