Re: .dk-TLD-problems
Andy Bradford <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
Thus said Tommy Mogensen on Wed, 09 Sep 2009 20:41:49 +0200: > Since Aug. 30th redelegation has included 'check for handeling lame > delegations'. This entails asking for a RR that is definetly not > hosted on the authoritative nameserver you want to redelegate to, and > expecting an NXDOMAIN answer. If the new authoritative nameservers do > not answer and the client has to timeout, the redelegation procedure > fails (output below), thus it is AFAIK not possible to redelegate to > namesevers running tinydns at all. I particularly like this behavior. I have seen a lot of ``backscatter'' attacks that target some other system by querying my server for . records, however, due to tinydns' design, my DNS server does not participate. You might want to inform DK-Hostmaster that by making this a requirement they are helping provide attack vectors for DoS authors. Andy -- [-----------[system uptime]--------------------------------------------] 9:08pm up 9 min, 1 user, load average: 1.07, 1.08, 0.64