Suivre

🇳🇪 .ne nameserver ― « it's just a drop in the bucket when it comes to these sorts of invalid configurations. »  [ 0xda.de/blog/2025/01/invalid-n ]

@minus Many (cc)TLDs do delegation validation checks to fight against this.
Of course, if there is already a malicious authoritative server configured for the domain the check will pass.
But at least, it may prevent lingering typos to become a later exploit without anybody but the attackers noticing.

@gjherbiet @minus Many ccTLDs? But far from the majority. And in fact some did in the past do checks, and stopped, like `.fr`. Also, it would be hard in advance for a malicious server to know which zones will suddenly be requested out of it, and even if it does some kind of wildcard, any trivial checks - like on NS recordset consistency across nameservers - would spot it (because the malicious one can't know in advance which ones are the other nameservers).

@minus Thanks for that study, insightful! Makes me remember another "recent" but ongoing kind of typo on TLDs but appearing in another part of the ecosystem: ft.com/content/ab62af67-ed2a-4

Inscrivez-vous pour prendre part à la conversation
nanao

Comme le soleil, les machines ne se couchent jamais.