[161980] in North American Network Operators' Group
Re: Open Resolver Problems
daemon@ATHENA.MIT.EDU (Scott Noel-Hemming)
Fri Mar 29 23:56:09 2013
Date: Fri, 29 Mar 2013 20:55:55 -0700
From: Scott Noel-Hemming <frogstarr78@gmail.com>
To: nanog@nanog.org
In-Reply-To: <13438.1364226293@turing-police.cc.vt.edu>
Reply-To: frogstarr78@gmail.com
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
On 03/25/2013 08:44 AM, Valdis.Kletnieks@vt.edu wrote:
> On Mon, 25 Mar 2013 15:38:01 -0000, Nick Hilliard said:
>> On 25/03/2013 14:33, Mikael Abrahamsson wrote:
>>> I would like to be able to request an IP list of open resolvers in my ASN,
>>> perhaps sent to the contact details in RIPE whois database to make sure I'm
>>> not falsely representing that ASN.
>> Why would that matter? This is publicly available information.
> Some of us have both publicly-facing authoritative DNS, and inward
> facing recursive servers that may be open resolvers but can't be
> found via NS entries (so the IP addresses of those aren't exactly
> publicly available info).
Sounds like your making the faulty assumption that an attacker would use
normal means to find your servers.
--
() ascii ribbon campaign - against html e-mail
/\ www.asciiribbon.org - against proprietary attachments