Re: [Full-Disclosure] food for thought -- root zone exposures

Valdis.Kletnieks_at_vt.edu
Date: 06/27/03

  • Next message: Shawn McMahon: "Re: [Full-Disclosure] Adminstrivia: Digest Limits/Netiquette"
    To: Len Rose <len@netsys.com>
    Date: Fri, 27 Jun 2003 14:20:39 -0400
    
    
    

    On Thu, 26 Jun 2003 23:25:06 EDT, Len Rose <len@netsys.com> said:

    > http://www.ietf.org/internet-drafts/draft-ietf-dnsop-bad-dns-res-01.txt
    >
    >
    > At the risk of appearing somewhat jaundiced, I'll bet someone
    > that it's an M$ nameserver implementation that they're
    > referring to.

    Section 3 (client) is a combination of NAT, poor configuration on the ISP's part,
    and MS's ActiveDirectory. The basic scenario is that you get a Windows box
    that gets DHCP'ed with an RFC1918 space, and it tries to register itself. The local
    DNS doesn't know squat about the space because it's misconfigued, so the client
    walks up the tree. The ISP fails to do ingress filtering, and things go pear-shaped quickly.

    And it's worse than that I-D says - see this for a hint HOW bad:

    http://www.nanog.org/mtg-0210/wessels.html

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: Shawn McMahon: "Re: [Full-Disclosure] Adminstrivia: Digest Limits/Netiquette"

    Relevant Pages

    • Re: Move mailbox provides server Netbios name instead of FQDN to Outlook
      ... My question is what is the exact mechanism for referring ... of the new server in the referral, ... this referral does not work because the client cannot resolve the ... >>how the Outlook client is redirected to the new server after a mailbox ...
      (microsoft.public.exchange.admin)
    • Re: Best practices for internal/external servers
      ... >less of a security risk than does an inbound VPN. ... >> anyone anywhere in the world to attempt to attack the IMAP server. ... Then if a client machine is compromised the only thing it'll be ...
      (comp.mail.imap)
    • Re: outlook on server
      ... I review each client individually. ... accept the risk, and willing to pay the bill to fix it, that's one thing. ... It's his server, his business. ...
      (microsoft.public.windows.server.sbs)
    • Re: [fw-wiz] VPN endpoints
      ... > 1) Some VPN products default to allowing the Null encryption algorithm. ... The cost of compromise is a function of the risk that the data may be ... > most of the benefits are in the fact that practically any client can be ...
      (Firewall-Wizards)
    • Re: What is the futur of Native Code ?
      ... >> driveup banking... ... That's because the risk is down ty $50, ... > efficiency and convenience of client-based software, ... the client is under complete control of the client owner. ...
      (borland.public.delphi.non-technical)