MLUG: [MLUG] DNS at UMC
[MLUG] DNS at UMC
Email address obfuscation in effect -- please click here to turn it off.

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
> There's always DNS poisoning. It's nailed some high-profile 
> places (Yankees,
> Hillary, etc.).

I haven't yet figured out how to defeat DNS poisoning in the design I've
built, partly because I don't entirely understand how the poisoning is
accomplished.

> The real risk is reconnaissance, but recon is the name of the 
> open-environment game such as a University

Not for long.  I am working on reducing the number of zones we host and the
number of name servers that we "officially" talk to.  Somewhere along the
path, only hosts with NS records in the zones we host will be allowed to do
zone transfers with us, and even then, probably not with noc.

After that, I'll be setting up digital keys so I can essentially
authenticate the hosts that *are* authorized to do the transfers.

--J
--
To unsubscribe, go to http://mlug.missouri.edu/members/edit.php

Archives are available at http://mlug.missouri.edu/list-archives/