prevent DNS attack

Michael Hoskins (michoski) michoski at
Thu Jun 28 02:55:13 UTC 2012

define "fake" -- if you mean rfc1918, you can block the ranges at ingress,
or with iptables or similar to avoid letting it hit bind at all.

-----Original Message-----
From: pangj <pangj at>
Date: Wednesday, June 27, 2012 6:36 PM
To: Tony Finch <dot at>
Cc: "bind-users at" <bind-users at>
Subject: Re: prevent DNS attack

>> There is also a patch for BIND which can help:
>Thank you.
>The traffic is incoming, and the incoming IPs are fake, how will the
>patch work to stop them?
>Email/Jabber/Gtalk: pangj at
>Free DNS Hosting with
>Please visit to
>unsubscribe from this list
>bind-users mailing list
>bind-users at

More information about the bind-users mailing list