Ranter
Join devRant
Do all the things like
++ or -- rants, post your own rants, comment on others' rants and build your customized dev avatar
Sign Up
Pipeless API
From the creators of devRant, Pipeless lets you power real-time personalized recommendations and activity feeds using a simple API
Learn More
Comments
-
@asgs that would be marvelous.
Or at least break it down to simple A / AAAA / SOA / MX record plus PTR. -
Did you already hardened your DNS against it being used as a mirror for reflection attacks?
-
@ScribeOfGoD
https://cloudflare.com/learning/...
EDNS and it's increase of possible payload made amplification/ mirror attacks pretty evil.
Not only becomes the quantity of requests a problem, but the bandwidth, too.
I think it was 4 kb for EDNS... Not much, unless you use amplification / mirroring...
Then the jump from 0.5 kb to 4 kb really hurts.
DNS is everywhere.
I hate DNS.
I hate DNS migrations.
I hate having a hundred plus DNS names inside my brain.
I hate resolving issues.
I hate DNSSEC.
I hate CNAMES.
I hate services which cannot be persuaded to stop trying AAAA resolves first.
I hate the fucking stupid braindead idea to use TXT as a configuration store inside DNS... And thus the necessity to blow up DNS query size aka EDNS.
I really really really really really want to burn this whole mfucking shit down...
rant
the forbidden and cursed lovecraft invention