Gentoo Archives: gentoo-user

From: Michael Mol <mikemol@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] How to prevent a dns amplification attack
Date: Fri, 29 Mar 2013 13:37:03
Message-Id: 515598EF.10707@gmail.com
In Reply to: Re: [gentoo-user] How to prevent a dns amplification attack by Alan McKinnon
1 On 03/29/2013 09:27 AM, Alan McKinnon wrote:
2 > On 29/03/2013 10:53, Norman Rieß wrote:
3 >>> That is just evil. Have you no alternative to this ISP?
4 >>>>
5 >>>>
6 >>>>
7 >>>> --
8 >>>>
9 >>>> Peter
10 >>>>
11 >>>>
12 >>>>
13 >> Like free and open DNS servers? ;-) Like the one i am talking about and
14 >> was told it was unnessesary crap?
15 >
16 >
17 > When you describe the service you DO get from your ISP, then we can see
18 > that rolling your own is the proper alternative for you. Unless your ISP
19 > block outbound port 53...
20
21 It'd be trivial enough for someone in a saner spot to privately offer
22 him an allowed-clients entry in a DNS server listening on a non-standard
23 port.
24
25 Either way, it's still important he not allow just anybody to connect to
26 his resolver.
27
28 >
29 > If you were in Africa, I could give you an alternative but sadly I don't
30 > think you are in Africa
31 >

Attachments

File name MIME type
signature.asc application/pgp-signature