> > > http://www.dnsstuff.com/tools/lookup.ch?name=www.google.com&type=A > > > &ser ver=ns1.webonthefly.com&detail=0 ), you are vulnerable to > > > them feeding your DNS server information on their domains, and > > > then listing your DNS servers as their authoritative servers. To > > > get around that, you would need to limit use of your DNS servers > > > to people who should have access to it. > > >Are you referring to recursion? > > That is correct. Then how would that help Dave?
Because if only "good" IPs have access to the DNS server, no "bad" people can poison it, and no "bad" people can benefit from having their NS records pointing to it.
Unknowingly he is the authoritve dns for example.com. He will advertise lame - my question is is there any way to prevent becoming the authority for a zone you have no knowledge of?
No. However, if he is running caching-only (recursive) DNS servers, and restricts access to his IP ranges only, then people will not be able to benefit from listing his DNS servers as being authoritative for their domains.
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask about our free 30-day evaluation.
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
