5 ms·
Nobody uses DNSSEC, so it's still easy to poison DNS caches I'm not sure if that's accurate - I believe source port randomization has made it extremely difficu
by trotsky 16y ago
Nobody uses DNSSEC, so it's still easy to poison DNS caches
I'm not sure if that's accurate - I believe source port randomization has made it extremely difficult to poison recursive DNS servers. I think a recent "successful" attack on source port randomizing showed it took them 7 hours on a 10Gb/s link to poison one A entry.