DNS Denial Of Service

Erik erik at colliander.pp.se
Wed Jun 23 07:04:24 UTC 1999


When and if DNSSEC is used globally all the way from the root servers and down
the hierarchy all the way, it will make it alot harder to poison cache.

"Davidson, Paul" wrote:

> This message is in MIME format. Since your mail reader does not understand
> this format, some or all of this message may not be legible.
>
> ------_=_NextPart_001_01BEBCDE.AE74A356
> Content-Type: text/plain;
>         charset="iso-8859-1"
>
> Does any version of BIND currently have protection against a DNS denial of
> Service attack. I understand this is accomplished by  sending invalid data
> to a DNS server ???????
>
>                           Paul Davidson
>               American International Group
> Work*:(973)-533-2754   Fax*: (973)-533-3777
>                   Beeper: (973)-719-1876
>             * paul.davidson2aig.com



More information about the bind-users mailing list