On MovieTome: Why you didn't see Shatner in TREK
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 2 of 26:
Next »
« Previous
He explained...
He said it was part of the way the protocol works. The way it comes across to me is that, when you respond with a legitimate A record, for say www.google.com, and you include a legitimate NS record, say ns1.google.com, you are now overriding whatever the cache says. That's one of the big problems with things as I see it.

Dan explained it's part of how stuff really works, part of that recursion in DNS. Basically, the DNS server got a valid response from you on www.google.com, why not believe that you also know about ns1.google.com?? And, since the cache nameserver value could have changed, I think this is part of the recursion method that allows systems to stay up to date.

-Nate
Posted by: nmcfeters   Posted on: 07/24/08 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

TTL  jahday | 07/24/08
He explained...  nmcfeters | 07/24/08
Close...  annominous | 07/24/08
Thanks for the clarification (NT)  nmcfeters | 07/24/08
Are private DNS servers exploitable?  NonZealot | 07/24/08
Not sure  nmcfeters | 07/24/08
Re: Are private DNS servers exploitable?  natron_ | 07/24/08
Re: Are private DNS servers exploitable?  natron_ | 07/24/08
Indeed.  jahday | 07/24/08
I'm 99% sure my router doesn't do DNS  NonZealot | 07/24/08
Unless  nmcfeters | 07/24/08
Yes  nmcfeters | 07/24/08
Yes and no  annominous | 07/24/08
Thanks for the answers, all of you  NonZealot | 07/24/08
Well... you might be a bigger target then you think  nmcfeters | 07/24/08
Yes, certainly vulnerable to that  NonZealot | 07/24/08
SuSE 10.2 works- DON'T UPGRADE  r_widell | 07/24/08
Has someone else confirmed this?  nmcfeters | 07/25/08
RE: Kaminsky suggests long-term fix will still have to be determined  annominous | 07/24/08
Indeed (NT)  nmcfeters | 07/24/08
Right.  jahday | 07/24/08
Actually  nmcfeters | 07/24/08
RE: TTL  natron_ | 07/24/08
Yes, this is correct  nmcfeters | 07/24/08
It would be better to handshake using UDP...  mrlinux | 07/25/08
RE: Kaminsky suggests long-term fix will still have to be determined, but patch now, or pay soon  phatkat | 07/25/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here