|
Not to cache TXT records in general sounds sort of detrimental to
the concept of a caching resolver. And apparently none of the
resolvers does evaluate which TXT records are legitimate and which
are useless/nefarious - as in being attempts of DNS tunnelling. TXT records might be required for SPF/DKIM/DMARC. NULL records on the other hand should perhaps not be cached, or even permitted for queries, considering https://tools.ietf.org/html/rfc1035 NULLs are used as placeholders in some experimental extensions of the DNS As far as I have read and understood the best protection against DNS Tunnelling is traffic analysis, e.g. firewall with deep packet inspection, and/or tools for payload analysis. On 22.11.2018 11:35, Unbound-users
wrote:
|
- IN TXT & NULL trash records Maciej Gawron via Unbound-users
- Re: IN TXT & NULL trash records ѽ҉ᶬḳ℠ via Unbound-users
- Re: IN TXT & NULL trash recor... A. Schulze via Unbound-users
- Re: IN TXT & NULL trash r... ѽ҉ᶬḳ℠ via Unbound-users
- Re: IN TXT & NULL trash r... Joe Abley via Unbound-users
- Re: IN TXT & NULL tra... ѽ҉ᶬḳ℠ via Unbound-users
- Re: IN TXT & NUL... Joe Abley via Unbound-users
- Re: IN TXT &... ѽ҉ᶬḳ℠ via Unbound-users
- Re: IN TXT &... ѽ҉ᶬḳ℠ via Unbound-users
- Re: IN TXT &... Maciej Gawron via Unbound-users
- Re: IN TXT &... Paul Vixie via Unbound-users
- Re: IN TXT &... Maciej Gawron via Unbound-users
