[Dnsmasq-discuss] Help in DNS amplification attack

Albert ARIBAUD albert.aribaud at free.fr
Thu Jul 16 11:34:44 BST 2015


Hi again AS,

Le Thu, 16 Jul 2015 15:39:56 +0530, "@shuToSH Ch at tURveDI"
<ashutosh.chaturvedi.31 at gmail.com> a écrit :

> NO,
> 
> i am using router from LAN i am sending query like (nslookup 1and1.com IP
> of LAN),
> and dnsmasq listening on LAN, and WAN Internet reachable.
> 
> i am also not sure this is issue or not.

Is your dnsmasq the autoritative name server for a domain that you
manage?

If not, then you don't need it to be reachable from outside the LAN,
and if you configure it to not be reachable from outside the LAN, then
it cannot be used for DNS amplification attacks.

> Thanks,
> AS

Amicalement,
-- 
Albert.



More information about the Dnsmasq-discuss mailing list