Skip to Content.
Sympa Menu

discuss - Re: [opennic-discuss] New domain to watch out for abuse - ddostheinter.net

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

Re: [opennic-discuss] New domain to watch out for abuse - ddostheinter.net


Chronological Thread 
  • From: Julian DeMarchi <julian AT jdcomputers.com.au>
  • To: discuss AT lists.opennicproject.org
  • Subject: Re: [opennic-discuss] New domain to watch out for abuse - ddostheinter.net
  • Date: Tue, 11 Jun 2013 16:22:27 +1000

On 06/11/2013 04:20 PM, Alex M (Coyo) wrote:
> On 06/11/2013 01:17 AM, Julian DeMarchi wrote:
>> On 06/11/2013 04:13 PM, Quinn Wood wrote:
>>> Perhaps instead of making claims that a zone won't be used for
>>> anything than attacks backed on its name, folks should perform
>>> heuristics checks on, I don't know, the actual zone.
>>>
>>> Any Tom, Dick, or Harry can register stopddos.est and pop the same
>>> records into it.
>> dig ddostheinter.net ANY
>>
>> ;; MSG SIZE rcvd: 8290
>>
>> This forces TCP.
>>
>> ]$ dig ddostheinter.net +short | wc -l
>> 511
>>
>> Why would someone have 511 A records for @....
>
> What would be the point of forcing a dns query to use TCP? What would an
> adversary gain?

TCP takes more overhead then UDP. It's also the increased packet size.
More wham value...

> What is a 511 record?

I meant 511 A forward records for @(ddostheinter.net)

--julian



Archive powered by MHonArc 2.6.19.

Top of Page