3 ms·
They could just set a low TTL
by willstrafach 8y ago
They could just set a low TTL
- iforgotpassword 8y agoNo they couldn't, unless they expect everyone to use a browser that is vulnerable to DNS rebind attacks, which probably means some browser from the 90s.
- r1ch 8y agoEvery browser is vulnerable to DNS rebind attacks, since the burden of "fixing" it has been pushed onto the applications that are getting traffic forwarded by the browser. Also services like Cloudflare wouldn't work if low TTLs didn't work. CF rotate IPs often as part of their DDoS protection.
- fps_doug 8y agoThey still do. Not like when DNS rebind was all the rage, where Firefox decided to cache DNS replies forever, but they still bump the TTL to a minimum of several minutes, which is enough to confuse people in the CP scenario. I wouldn't be surprised if some OS resolvers did the same, possibly just for performance reasons even. And that's all fine and dandy since those couple minutes don't break the Cloudflare scenario. I mean, if it weren't the case, why would CPs work in that way then anyways? It wouldn't be an issue to have a DNS server in the mix that resolves everything to you CP address with a TTL of one second, and then additionally to your port 80 TCP redirect just add another one for 53 UDP. It's not being done by any CP solution I have ever encountered.