Always return a SERVFAIL response to DNS queries with RD=0.
Unless we are acting in authoritative mode, obviously. To do otherwise may allows cache snooping, see. http://cs.unc.edu/~fabian/course_papers/cache_snooping.pdf
Showing
Please register or sign in to comment