On Thu, 5 Mar 2015, Tony Finch wrote:

* ANY always returns a TTL of 5 seconds.

That 5 second TTL is an artefact of RPZ processing. By default BIND
returns the upstream TTL in responses to ANY queries.

Really? Wouldn't that _contribute_ to DDOS attacks when the attacker
uses open recursives to attack the authoritative servers?

Paul
_______________________________________________
dns-operations mailing list
[email protected]
https://lists.dns-oarc.net/mailman/listinfo/dns-operations
dns-jobs mailing list
https://lists.dns-oarc.net/mailman/listinfo/dns-jobs

Reply via email to