BugTraq
Verisign abusing .COM/.NET monopoly, BIND releases new Sep 17 2003 03:16AM
Thor Larholm (thor pivx com) (2 replies)
Re: Verisign abusing .COM/.NET monopoly, BIND releases new Sep 17 2003 09:28PM
SR (bugtraq rivera za net) (1 replies)
Re: Verisign abusing .COM/.NET monopoly, BIND releases new Sep 17 2003 10:19PM
Damaged Industries (damaged damaged no-ip com) (1 replies)
RE: Verisign abusing .COM/.NET monopoly, BIND releases new Sep 18 2003 08:39PM
bugtraq (bugtraq arcanasystems com)
Re: Verisign abusing .COM/.NET monopoly, BIND releases new Sep 17 2003 09:19PM
Jose Nazario (jose monkey org)
a number of options exist to help you remedy this issue:

- bind 9.2.3rc2 supports "delegation-only", stopping some
wildcard implementations from making any difference

if you simply want to stop traffic getting there (they are running a
website and a partially functional MTA on that IP):

- you can BGP null route this
http://www.merit.edu/mail.archives/nanog/msg13715.html

- cisco's NBAR functionality may be used to detect and block those
reply packets from coming in by looking for the response from
the nameservers.
http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121newft
/121limit/121e/121e2/nbar2e.htm

note that this wont stop the query from reaching verisign, it will just
stop you from going to that IP. however, for some enforcing network
privacy concerns, that may be worthwhile.

hope this helps,

___________________________
jose nazario, ph.d. jose (at) monkey (dot) org [email concealed]
http://monkey.org/~jose/

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus