Skip to Content.
Sympa Menu

discuss - Re: [opennic-discuss] New domain to watch out for abuse - ddostheinter.net

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

Re: [opennic-discuss] New domain to watch out for abuse - ddostheinter.net


Chronological Thread 
  • From: "Alex M (Coyo)" <coyo AT darkdna.net>
  • To: discuss AT lists.opennicproject.org
  • Subject: Re: [opennic-discuss] New domain to watch out for abuse - ddostheinter.net
  • Date: Tue, 11 Jun 2013 01:20:07 -0500

On 06/11/2013 01:17 AM, Julian DeMarchi wrote:
On 06/11/2013 04:13 PM, Quinn Wood wrote:
Perhaps instead of making claims that a zone won't be used for
anything than attacks backed on its name, folks should perform
heuristics checks on, I don't know, the actual zone.

Any Tom, Dick, or Harry can register stopddos.est and pop the same
records into it.
dig ddostheinter.net ANY

;; MSG SIZE rcvd: 8290

This forces TCP.

]$ dig ddostheinter.net +short | wc -l
511

Why would someone have 511 A records for @....

What would be the point of forcing a dns query to use TCP? What would an adversary gain?

What is a 511 record?



Archive powered by MHonArc 2.6.19.

Top of Page