Re: ANY queries to tinydns

Matthew Dempsky <[email protected]> Wed, 31 Mar 2010 13:46:57 -0700
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Wed, Mar 31, 2010 at 1:34 PM, Dean Anderson <[email protected]> wrote:
> I can't imagine why firewall should have problems with
> such a packet, but that's on the firewall.

Because most DNS software sets the numrecords fields based on the
number of records included in the response, so sloppy firewall
builders assume this is the correct/only behavior and add paranoid
rules to their firewalls to reject other responses as malicious
attempts to exploit buggy client software.