On Mon, Jul 24, 2000 at 10:54:38PM +1200, Chris, the Young One wrote:
> On Mon, Jul 24, 2000 at 03:47:03AM -0700, Russ Allbery wrote:
> ! Ricardo Cerqueira <[EMAIL PROTECTED]> writes:
> ! > Wrong. You can perform zone transfers on MAPS' nameservers :-) That'll
> ! > give you the entire list.
> ! 
> ! Without signing the document?
> 
> Yes. DJB has posted on [EMAIL PROTECTED] a side-channel means of
> getting it, by exploiting BIND features (which don't include AXFR,
> despite Ricardo's use of the words ``zone transfers'').
> 

Chris...

        It's been blocked somewhere since I wrote that mail:

---- then ---
$ dig @NS-EXT.VIX.COM axfr relays.mail-abuse.org

; <<>> DiG 8.2 <<>> @NS-EXT.VIX.COM axfr relays.mail-abuse.org 
; (1 server found)
$ORIGIN relays.mail-abuse.org.
@                       1D IN SOA       @ iverson.mail-abuse.org. (
                                        964432803       ; serial
                                        10M             ; refresh
                                        5M              ; retry
                                        1W              ; expiry
                                        30M )           ; minimum
[etc...]
XX.88.XXX.130           5M IN A         127.0.0.2
                        5M IN TXT       "Open relay problem - see 
<URL:http://www.mail-abuse.org/cgi-bin/nph-rss?130.XXX.88.XX>"
XXX.240.XXX.130         5M IN A         127.0.0.2
                        5M IN TXT       "Open relay problem - see 
<URL:http://www.mail-abuse.org/cgi-bin/nph-rss?130.XXX.240.XXX>"
[etc, etc, etc...]
--------------- (The XXX were placed by me)


and now, it refuses the query :-) 


RC

PS: I guess the mail I was writing to them isn't necessary anymore :)

-- 
+-------------------
| Ricardo Cerqueira  
| PGP Key fingerprint  -  B7 05 13 CE 48 0A BF 1E  87 21 83 DB 28 DE 03 42 
| Novis  -  Engenharia ISP / Rede Técnica 
| Pç. Duque Saldanha, 1, 7º E / 1050-094 Lisboa / Portugal
| Tel: +351 21 3166700 (24h/dia) - Fax: +351 21 3166701

Reply via email to