LWN.net Logo

BIND 9 denial of service being seen in the wild

BIND 9 denial of service being seen in the wild

Posted Nov 17, 2011 17:12 UTC (Thu) by jhardin (guest, #3297)
Parent article: BIND 9 denial of service being seen in the wild

One thing I haven't seen explicitly addressed: if named is configured with "recursive no" is it immune?


(Log in to post comments)

BIND 9 denial of service being seen in the wild

Posted Nov 17, 2011 18:06 UTC (Thu) by jeleinweber (subscriber, #8326) [Link]

Apparently the attack scenario involves a recursive query which hits a rogue server that provides an NXDOMAIN result with attached resource records.

Iterative only (authoritative) servers should be immune, yes.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds