[nsp-sec] Port 53 Blocking on DSL/Cable Networks

jonathan.curtis at bell.ca jonathan.curtis at bell.ca
Thu Jan 31 13:16:15 EST 2008



Has anyone taken a serious look at blocking these ports externally on
their networks?

Reasons I ask:

1. Prevent Home Gateway Pharming / Phishing

http://www.news.com/8301-10789_3-9855195-57.html 

http://www.cert.org.mx/imagenes/dns.png



2. Protect TLD's and Root Servers from direct attacks from Cable - DSL
customers


If you have looked at it, did you record a list of public open DNS
server IP's that you could share?


Thanks,

Jonathan

AS 577







More information about the nsp-security mailing list