> > > http://www.dnsstuff.com/tools/lookup.ch?name=www.google.com&type=A
> > > &ser ver=ns1.webonthefly.com&detail=0 ), you are vulnerable to
> > > them feeding your DNS server information on their domains, and
> > > then listing your DNS servers as their authoritative servers.  To
> > > get around that, you would need to limit use of your DNS servers
> > > to people who should have access to it.
> 
> >Are you referring to recursion?
> 
> That is correct.
Then how would that help Dave? Unknowingly he is the authoritve dns 
for example.com. He will advertise lame - my question is is there any 
way to prevent becoming the authority for a zone you have no 
knowledge of?

Thanks!

                -Nick


 


> 
> >If so how would that work? If your dns is the authority it would not
> >block this - correct? How could it be done?
> 
> There are 3 types of DNS servers:
> 
> [1] Authoritative only.  These are used to answer queries about your
> domains.  It is best if these do not have recursion/caching enabled,
> which makes it impossible for cache corruption to occur.
> 
> [2] Caching only.  These are used to answer queries about other 
> domains.  It is best if access is restricted to IPs under your 
> control.  However, there are many large ISPs who have caching DNS
> servers that are publicly accessible.  Cache poisoning, if the DNS
> server isn't protected against it, can be a problem (but only for
> people who use the caching-only DNS server -- not for people who are
> accessing your own domains, as they will go to the authoritative-only
> server).
> 
> [3] Combination authoritative and caching.  This is not recommended,
> as it can potentially allow cache poisoning of your own domains.  If
> the DNS server is good, however, cache poisoning should not be
> possible.
> 
>                                    -Scott
> ---
> Declude JunkMail: The advanced anti-spam solution for IMail
> mailservers. Declude Virus: Catches known viruses and is the leader in
> mailserver vulnerability detection. Find out what you've been missing:
> Ask about our free 30-day evaluation.
> 
> ---
> [This E-mail was scanned for viruses by Declude Virus
> (http://www.declude.com)]
> 
> 
> To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
> List Archive:
> http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge
> Base/FAQ: http://www.ipswitch.com/support/IMail/
> 



To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to