[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <87myjf7pb8.fsf@mid.deneb.enyo.de>
Date: Thu, 14 Aug 2008 14:29:15 +0200
From: Florian Weimer <fw@...eb.enyo.de>
To: Paul Szabo <psz@...hs.usyd.edu.au>
Cc: full-disclosure@...ts.grok.org.uk
Subject: Re: DNS forward only: why does it help?
* Paul Szabo:
> As a workaround, it is recommended to set DNS servers to forward only.
> Can someone explain why that helps?
It helps if the network between recursor and forwarder is trusted. If
it's not, the attacker must still obtain the IP addresses involved and
the forwarder source port, which doesn't immediately leak to the
attacker. So automated attacks are somewhat less likely.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists