TLD servers with recursion was Re: Exploit for DNS Cache Poisoning - RELEASED

2008-07-24 Thread Simon Waters
On Thursday 24 July 2008 05:17:59 Paul Ferguson wrote: Let's hope some very large service providers get their act together real soon now. http://www.hackerfactor.com/blog/index.php?/archives/204-Poor-DNS.html It isn't going to happen without BIG political pressure, either from users, or

Re: TLD servers with recursion was Re: Exploit for DNS Cache Poisoning - RELEASED

2008-07-24 Thread John Kristoff
On Thu, 24 Jul 2008 10:06:25 +0100 Simon Waters [EMAIL PROTECTED] wrote: I checked last night, and noticed TLD servers for .VA and .MUSEUM are still offering recursion amongst a load of less popular top level domains. Indeed just under 10% of the authoritative name servers mentioned in the

Re: TLD servers with recursion was Re: Exploit for DNS Cache Poisoning - RELEASED

2008-07-24 Thread Gadi Evron
On Thu, 24 Jul 2008, John Kristoff wrote: On Thu, 24 Jul 2008 10:06:25 +0100 Simon Waters [EMAIL PROTECTED] wrote: I checked last night, and noticed TLD servers for .VA and .MUSEUM are still offering recursion amongst a load of less popular top level domains. Indeed just under 10% of the

Re: TLD servers with recursion was Re: Exploit for DNS Cache Poisoning - RELEASED

2008-07-24 Thread Gadi Evron
On Thu, 24 Jul 2008, Gadi Evron wrote: But sticking to the point, TLD servers should (under most circumstances) be Should NEVER, oops.

RE: TLD servers with recursion was Re: Exploit for DNS Cache Poisoning- RELEASED

2008-07-24 Thread Gadi Evron
On Thu, 24 Jul 2008, Martin Hannigan wrote: I personally know several folks from within and wayyy from outside the DNS world who discovered this very out there and obvious issue and worked hard to try and contact the operators. Those that haven't fixed it yet, likely won't if all thing

Re: TLD servers with recursion was Re: Exploit for DNS Cache Poisoning- RELEASED

2008-07-24 Thread Steven M. Bellovin
On Thu, 24 Jul 2008 15:50:15 - Martin Hannigan [EMAIL PROTECTED] wrote: I don't know that a failure to act immediately is indicative of ignoring the problem. Not to defend ATT or any other provider, but it's not as simple as rolling out a patch. Right. What scares me is all of the

Re: TLD servers with recursion was Re: Exploit for DNS Cache Poisoning- RELEASED

2008-07-24 Thread Gadi Evron
On Thu, 24 Jul 2008, Steve Bertrand wrote: Gadi Evron wrote: On Thu, 24 Jul 2008, Martin Hannigan wrote: I personally know several folks from within and wayyy from outside the DNS world who discovered this very out there and obvious issue and worked hard to try and contact the operators.