nanog mailing list archives

Re: Multiple DNS implementations vulnerable to cache poisoning


From: Jean-François Mezei <jfmezei () vaxination ca>
Date: Wed, 09 Jul 2008 00:04:33 -0400

Re: the tool

My DNS server does not serve the outside world. Incoming packets to port
53 are NAT directed to an non-existant IP on the LAN.

The tool uses my internet facing IP as my DNS server and tells me I am
vulnerable. Since, from the internet, connecting to that IP at port 53
will not get you to a DNS server, I find the tool's conclusion rather
without much value.




Current thread: