[Gllug] so after the DNS - Attack

Alain Williams addw at phcomp.co.uk
Wed Feb 7 14:14:36 UTC 2007


On Wed, Feb 07, 2007 at 02:01:35PM -0000, Juergen Schinker wrote:
> Am Mi, 7.02.2007, 10:59, schrieb Jason Clifford:
> 
> 
> > People generally do not run their own name servers but rather use their
> > ISP's CACHING name servers.
> >       ^^^^^^^
> >
> the Caches will soon be empty

Expiry time (as from my box) for the root servers is 3 days -- a long time
for a DDOS to continue. What I could loose is the NS records for the TLDs,
for the UK that seems to be 2 days ... still a long time.

I have put orsn.hint up in my bind config but commented it out ... so I could
quickly switch if things did come bad. Probably over cautious, but it only took
5 minutes.


Putting a different hat on, this issue has raised a lot of steam. Would the
gllug readership attend a 1 day conference dealing with DNS stability/security/...
if UKUUG were to put one on ? If so, what topics would you like to see discussed ?

Cheers

-- 
Alain Williams
Linux Consultant - Mail systems, Web sites, Networking, Programmer, IT Lecturer.
+44 (0) 787 668 0256  http://www.phcomp.co.uk/
Parliament Hill Computers Ltd. Registration Information: http://www.phcomp.co.uk/contact.php
#include <std_disclaimer.h>
-------------- next part --------------
-- 
Gllug mailing list  -  Gllug at gllug.org.uk
http://lists.gllug.org.uk/mailman/listinfo/gllug


More information about the GLLUG mailing list