So, the cat is out of the bag. The DNS theoretical flaw is now real, with
exploit code written. It currently takes a couple minutes, but it can be changed to take a few seconds. It has to do with sloppy reception of RR records really. I wrote a bit of code today to try to get it accept an alternate address, and I came pretty close. But not
(
Read more... )