> http://www.dnsstuff.com/tools/lookup.ch?name=www.google.com&type=A&ser
> ver=ns1.webonthefly.com&detail=0 ), you are vulnerable to them feeding
> your DNS server information on their domains, and then listing your
> DNS servers as their authoritative servers.  To get around that, you
> would need to limit use of your DNS servers to people who should have
> access to it.

Are you referring to recursion?

That is correct.


If so how would that work? If your dns is the authority it would not block this - correct? How could it
be done?

There are 3 types of DNS servers:


[1] Authoritative only. These are used to answer queries about your domains. It is best if these do not have recursion/caching enabled, which makes it impossible for cache corruption to occur.

[2] Caching only. These are used to answer queries about other domains. It is best if access is restricted to IPs under your control. However, there are many large ISPs who have caching DNS servers that are publicly accessible. Cache poisoning, if the DNS server isn't protected against it, can be a problem (but only for people who use the caching-only DNS server -- not for people who are accessing your own domains, as they will go to the authoritative-only server).

[3] Combination authoritative and caching. This is not recommended, as it can potentially allow cache poisoning of your own domains. If the DNS server is good, however, cache poisoning should not be possible.

-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask about our free 30-day evaluation.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to