3 ms·
Soon your daughter will learn: it's always DNS
by PrimHelios 9y ago
Soon your daughter will learn: it's always DNS
- utefan001 9y agoThat's right! My other project is something I think is very powerful, but nobody so far seems to be to interested. Throwing it out in case someone wants try it. If you pay attention to malware analysis you will see raw IP addresses and random domains are very common in malware. I think corps should enable their outbound firewalls. Problem now is whitelisting each IP is way too much work. My tests show a C++ DNS proxy can be used to whitelist IP addresses to ipset hash in iptables just before the DNS proxy responds to client. Raw IPs are now blocked and firewall outbound is coupled to your trusted DNS provider. This would massively reduce attack surface to domains your org regularly uses. Not resolving new / young domains is important here. At this point we can blame DNS and the firewall!
- laxk 9y agoMy son is smart enough to change DNS IPs to google public DNS servers and the most ridiculous thing is that he studied it on the khanacademy site. :)