nanog mailing list archives
Re: On-going Internet Emergency and Domain Names
From: Paul Vixie <vixie () vix com>
Date: 31 Mar 2007 06:09:30 +0000
whoa. this is like deja vu all over again. when barb@CERT asked me to patch BIND gethostbyaddr() back in 1994 or so to disallow non-ascii host names in order to protect sendmail from a /var/spool/mqueue/qf* formatting vulnerability, i was fresh off the boat and did as i was asked. a dozen years later i find that that bug in sendmail is long gone, but the pain from BIND's "check-names" logic is still with us. i did the wrong thing and i should have said "just fix sendmail, i don't care how much easier it would be to patch libc, that's just wrong." are we really going to stop malware by blackholing its domain names? if so then i've got some phone calls to make. -- Paul Vixie
Current thread:
- Re: On-going Internet Emergency and Domain Names (kill this thread), (continued)
- Re: On-going Internet Emergency and Domain Names (kill this thread) Petri Helenius (Mar 31)
- Re: On-going Internet Emergency and Domain Names Peter Thoenen (Mar 31)
- Re: On-going Internet Emergency and Domain Names Fergie (Mar 30)
- Re: On-going Internet Emergency and Domain Names Jeff Shultz (Mar 30)
- Re: On-going Internet Emergency and Domain Names Gadi Evron (Mar 30)
- Re: On-going Internet Emergency and Domain Names Steven M. Bellovin (Mar 30)
- Re: On-going Internet Emergency and Domain Names Matt Ghali (Mar 31)
- Re: On-going Internet Emergency and Domain Names Jeff Shultz (Mar 30)
- Re: On-going Internet Emergency and Domain Names Fergie (Mar 30)
- Re: On-going Internet Emergency and Domain Names Fergie (Mar 30)
- Re: On-going Internet Emergency and Domain Names Mark Green (Mar 30)
- Re: On-going Internet Emergency and Domain Names Paul Vixie (Mar 30)
- Re: On-going Internet Emergency and Domain Names Suresh Ramasubramanian (Mar 31)
- Re: On-going Internet Emergency and Domain Names Adrian Chadd (Mar 31)
- Re: On-going Internet Emergency and Domain Names Suresh Ramasubramanian (Mar 31)
- Re: On-going Internet Emergency and Domain Names Adrian Chadd (Mar 31)
- Re: On-going Internet Emergency and Domain Names Suresh Ramasubramanian (Mar 31)
- Re: On-going Internet Emergency and Domain Names Mark Green (Mar 30)
- Re: On-going Internet Emergency and Domain Names Gadi Evron (Mar 31)
- Re: On-going Internet Emergency and Domain Names Mikael Abrahamsson (Mar 31)
- Re: On-going Internet Emergency and Domain Names Gadi Evron (Mar 31)
- Re: On-going Internet Emergency and Domain Names Peter Dambier (Mar 31)
- Re: On-going Internet Emergency and Domain Names Kradorex Xeron (Mar 31)