Re: COZA: FAIL: Nameserver information (FQDN/IP) mismatch
Hendrik Visage <
hvjunk@...>
2005-06-01 08:40:00 GMT
On 6/1/05, Russell Cloran <russell@...> wrote:
> Hi,
>
> I'm not sure why you replied to this off-list...
Just call it GMAIL.
>
> On Wed, 2005-06-01 at 00:51 +0200, Hendrik Visage wrote:
> > > The problem is well documented by Dan Bernstein at
> > > http://cr.yp.to/djbdns/notes.html
> >
> > Dan Bernstein have been tainting the real issues with his personal views IMO.
> >
> > He might make valid points, but sometimes missing the plot :( His
> > explanation there I can at least give one example how with the right
> > implementation inside the DNS servers, the damages will be near zero
> > with the glue records.
>
> Please, do share your example?
Re valid points etc.: Refer to qmail's distribution license, and his
total ignorance of things like the Linux file layout/hierarchy
standard etc. not to mention overdesign/kill (IMO) of qmail, but again
that is subjective.
If you refered to DNS, the way DNS get's information regarding NS
record's A records and the whole cache poisoning, it all related to
how/when the dns server use and supply the glue record. If you receive
the glue record as part of a NS lookup/request, it should be marked
accordingly and only used for that domain it refers to. Memory abuse
(Continue reading)