Re: maybe a dumb idea on how to fix the dns problems i don't know....

2008-08-09 Thread Matt F
Why not just require TCP for a lookup if a response with an incorrect TXID is received? You could require TCP for just the one lookup or for some configured interval, say 1 hour. That should slow attackers down substantially. Joe Abley wrote: On 9 Aug 2008, at 17:22, Church, Charles wrote:

Re: Great Suggestion for the DNS problem...?

2008-07-28 Thread Matt F
What would the ip-blocking BGP feed accomplish? Spoofed source addresses are a staple of the DNS cache poisoning attack. Worst case scenario, you've opened yourself up to a new avenue of attack where you're nameservers are receiving spoofed packets intended to trigger a blackhole filter, bloc