bloxHub

www.infoblox.com/community

Cricket on DNS

The latest on DNS Security, DNSSEC, IP Address Management... and more

rss
Cricket Liu on October 24, 2012

It's an unfortunate fact of life that name servers are exploited by malware.  Malware queries name servers to map the domain names that identify their command and control channel to IP addresses.  Malware uses DNS as a channel over which to transmit new code.  And  some malware targets name servers with distributed denial of service attacks.

The latest versions of BIND, however, enable DNS administrators to turn the tables on malware.

Cricket Liu on July 08, 2012

I remember years ago, Infoblox hired our first real IT guy (my friend Nate Campi).  Not long afterward, Nate tightened up our firewall rules--et voila, I could no longer query name servers on the Internet directly.  I bristled at this, and asked Nate his rationale for cutting off our access.  We couldn't run dig and nslookup from our clients anymore!

Cricket Liu on April 30, 2012

Back in October 2010, I posted Whither DNSSEC? which speculated on DNSSEC's second act. If the Internet had a fully DNSSEC-secured namespace, we could add email authorization data and SSH fingerprints to DNS. Two commenters, Chris Angelico and John Speno, suggested storing web site certificates and certs for signing applets in DNS, too.

Pages

Welcome to bloxHub

Welcome to bloxHub, our community for users of Infoblox products. Most of our content can be viewed as a guest, but if you wish to contribute or join a conversation, you will need to log in. If you don't have a bloxHub account, we invite you to register an account and join us.

Follow us on Twitter

Follow us on Twitter at @bloxHub and we'll keep you notified of new content on the community as well as webinars and other items of interest to Infoblox users.