Interesting indeed but I am wondering whether there is a difference in the semantics of NULL records (rfc1035) and DNS query of type NULL (rfc8145).

One refers to a record and the other to a query type, with NULL overlapping and introducing a confusion, but albeit seeming to refer to different semantics?

And it seems unlikely that a Key Tag query could be utilized for any benefit in malicious DNS tunnelling.

On 22.11.2018 14:38,  via Unbound-users wrote:

ѽ҉ᶬḳ℠ via Unbound-users:

NULL records on the other hand should perhaps not be cached, or even
permitted for queries, considering     https://tools.ietf.org/html/rfc1035

interesting, that may break signaling trust anchor knowledge
https://tools.ietf.org/html/rfc8145#section-5.1

Andreas




Reply via email to