Vulnerability to cache poisoning -- the rest of the solution

Alan Clegg Alan_Clegg at isc.org
Mon Jul 14 14:44:16 UTC 2008


Jeff Lightner wrote:
> If that's the case why wouldn't we have needed to open firewall to allow
> this behavior for tcp?
You would have.  Unless you never had (functional) DNS queries/transfers
over TCP.

AlanC





The information contained in this message and any attachment may be
proprietary, confidential, and privileged or subject to the work
product doctrine and thus protected from disclosure.  If the reader
of this message is not the intended recipient, or an employee or
agent responsible for delivering this message to the intended
recipient, you are hereby notified that any dissemination,
distribution or copying of this communication is strictly prohibited.
If you have received this communication in error, please notify me
immediately by replying to this message and deleting it and all
copies and backups thereof.  Thank you.




More information about the bind-users mailing list