On MovieTome: 10 Awesome Alien Movies
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 9 of 14:
Next »
« Previous
Nice concept, and a clarification....
Maxo,
(1) I like your concept. I use a somewhat similar technique on my own network's access to the internet. I use a local DNS, with verification against the upstream DNS servers done in the background, and an alert is raised if a local DNS entry's I/P address no longer matches that of the upstream DNS entry, so that it can then be investigated. Works great for almost five years now.
(2) The clarification: In your last sentence of your post, are you referring to the ROOT DNS servers? If so, there are, in fact, 13 of them. There are thousands of DNS servers all over the internet, arranged in a hierarchical fashion. If your request is for a DNS entry which is not in the closest DNS server to your connection, the DNS request is sent up the chain, until it is either resolved, or results in a "404" error (not found). It it rarely the case that a DNS request actually gets to any of the 13 root servers, since the request is typically resolved by a DNS server much closer to the requester. That is the reason the attack on the DNS root servers a while ago didn't get noticed by most users, and also why it takes time to map a domain name to an I/P address, like when you register a domain name and set up a hosting account.

If everybody on the net was banging on the 13 root DNS servers, there would BE no internet! happy
Posted by: kenetrix@...   Posted on: 03/09/05 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Don't use DNS if you care about security  NonZealot | 03/08/05
nice.. i give that a 7 (nt)  xshakes | 03/08/05
You really are not totally secure  osreinstall | 03/08/05
On the wall  SC-man | 03/09/05
You still didn't get me.  osreinstall | 03/09/05
*ahem*  linuxoverwindows | 03/09/05
Interesting concept... LOCAL DNS.  maxo_z | 03/08/05
10 dns servers?  linuxoverwindows | 03/09/05
Nice concept, and a clarification....  kenetrix@... | 03/09/05
I don't think he meant the root servers  voska | 03/09/05
re: I don't think he meant the root servers  kenetrix@... | 03/09/05
not to nitpick...  linuxoverwindows | 03/09/05
re: not to nitpick...  kenetrix@... | 03/09/05
ahh, we all knew what ya meant anyway happy nt  linuxoverwindows | 03/09/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads