Re: SPF records and DKIM signatures on ubuntu/postfix/mailman

Martin D Kealey <[email protected]>
Newsgroups gmane.org.user-groups.linux.new-zealand.general
Message-ID <[email protected]>
On Sat, 15 Oct 2011, Volker Kuhlmann wrote:
> The reason for blocking requests from non-customers has more to do with
> "why do something for the competition" than any security.

There are exploits in the wild that can poison a DNS cache, based on
guessing (read "brute-forcing") request ID numbers.

A good way to guard against your ISPs resolver cache getting poisoned is
simply not to use it: run your own resolver instead. But most people won't
do that.

Restricting requests to "just customers" will cut by three orders of
magnitude the number of 'bots that can attack you. (Or at least, it will if
you're a "small" ISP, being one whose customers comprise less than 0.1% of
worldwide internet users, which includes every ISP in NZ including Xtra.)

Another way to reduce the chances of an attack succeeding is to use
different outgoing IP addresses for incoming and outgoing queries. Running
many small DNS caches behind a load balancer (rather than just a few large
ones) also helps.

-Martin

_______________________________________________
NZLUG mailing list [email protected]
http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.