Thursday, July 30, 2009

DNS-Redirects

Nobody likes DNS-Redirects. Even IETF said recently (http://www.icann.org/en/committees/security/sac041.pdf):

The redirection and synthesizing of DNS responses by TLDs poses a clear and significant
danger to the security and stability of the domain name system. The consequences of
synthesized DNS responses range from erosion of trust relationships to the creation of
new opportunities for malicious attacks, without the ability of the affected party(ies) to mitigate these problems.


Serversniff stumbles over this shit, too. Currently the TLDs .mobi, .jobs and .asia use this - they answer every dns-request with an ip, even if a domain won't exist.

They don't dare to present a http-landing-page (like e.g. t-online.de does) - but in fact they resolve every query to an IP, misleading quite a few of serversniff's scripts. We're workin to fix this - but this takes time, for we need to fix every ip-lookup-routine.

totally useless shit.

tom

1 comment:

Voyance serieuse said...

It’s really a nice and useful piece of info. I’m glad that you shared this useful info with us. Please keep us up to date like this. Thank you for sharing.