4 ms·
So, what exactly is the best way to mitigate this attack vector? While informative, the post only goes into detail about the attack; not a complete solution for
by ericcholis 9y ago
So, what exactly is the best way to mitigate this attack vector? While informative, the post only goes into detail about the attack; not a complete solution for the original intended purpose of the resolver setting.
Is the dnsmasq solution here[1] sufficient? Or, should I edit dhclient.conf to add the desired name servers[2]
[1] https://unix.stackexchange.com/questions/128220/how-do-i-set-my-dns-when-resolv-conf-is-being-overwritten#163506 https://unix.stackexchange.com/questions/128220/how-do-i-set...
[2] https://unix.stackexchange.com/questions/128220/how-do-i-set-my-dns-when-resolv-conf-is-being-overwritten#154538 https://unix.stackexchange.com/questions/128220/how-do-i-set...
- mrb 9y agoUsing "resolver 127.0.0.1" is an effective mitigation against all issues I documented.