3 ms·
Well, that title was a little misleading, but it's still not an encouraging tale. What's the fix here?
by S_Daedalus 10y ago
Well, that title was a little misleading, but it's still not an encouraging tale. What's the fix here?
- Animats 10y agoMaybe limit DNS queries with long answers to TCP. DNS servers speak both TCP and UDP. With a UDP query, the source address can be faked, which causes the results to be sent somewhere else. With TCP, the attacker can't make it through the TCP handshake with a fake source address, because the attacker isn't getting the replies.