In message <20180322140233.ga79...@staff.retn.net>, 
Alexandre Snarskii <s...@snar.spb.ru> wrote:

>DNS: if both A and A' running open recursive DNS servers (bad idea in 
>modern internet, but..) it's possible to use TTL field to differentiate.
>Scenario: create some DNS record with good enough TTL of one hour. Ask A 
>about this record, get answer with TTL = 3600. Wait for ten seconds, then
>ask A' about the same record. If received TTL is about 3590 - it's really
>likely that A and A' is the same host.

Thank you!  Yes.  This, and checking the SSH key, seem to both be very
promising solutions to the problem.

I will be investigating and trying both, to try to establish how well
they might work in practice.

It will be great if both work, because some bad actors will be running
SSH (on a known or findable port) and others won't be.  And likewise,
some bad actors will be running their own name servrs and others won't
be.  So it will be Good to have several tools in the toolbox.
_______________________________________________
freebsd-net@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "freebsd-net-unsubscr...@freebsd.org"

Reply via email to