[20561] in North American Network Operators' Group
Re: WARNING: AOL is hosed (again)
daemon@ATHENA.MIT.EDU (James Rishaw)
Fri Oct 16 16:25:23 1998
In-Reply-To: <Pine.LNX.3.95.981016121152.11834A-100000@ruby.he.net> from Mike Leber at "Oct 16, 98 12:58:05 pm"
To: mleber@he.net
Date: Fri, 16 Oct 1998 15:11:28 -0500 (CDT)
Cc: markb@infi.net, nanog@merit.edu
From: jamie@dilbert.ais.net (James Rishaw)
Reply-To: jamie@ais.net
Mike Leber wrote:
> On Fri, 16 Oct 1998, Mark Borchers wrote:
> > Yep, somebody modified the delegation via a forged domain
> > modification email. An emergency root server update has been done to
> > correct the problem.
>
> Isn't an acknowlegement required with the correct tracking number?
>
> If yes, were acknowlegement(s) also forged with guessed tracking numbers?
>
> If yes to my second question, then the tracking numbers either need to be
> made much longer and randomized or a one time pass phrase (session key)
> needs to be added to the acknowlegement form.
You can actually set a domain name so that it cannot be changed, by
any template, by any modification, correct guardian or NOT.
I would ass-u-me AOL did this, but obviously their DNS admins aren't
clued enough to figure this one out.
Tiem to hire people that know *all* of what they're supposed to do, not
just what they read out of an ORA book.
Gah.
--
jamie rishaw (efnet:gavroche) American Information Systems, Inc.
Tel:312.425.7140, FAX:312.425.7240
-- Your silence will NOT protect you. --
"Did they just ask Don King to come to the lobby?!" - davidr