Re: [SLE] Subnet 169.254.0.0 (fwd)

From: Anders Johansson (andjoh_at_rydsbo.net)
Date: 08/24/04

  • Next message: Tom Nielsen: "Re: [SLE] KDE's Remote Desktop...question"
    To: suse-linux-e@suse.com
    Date: Tue, 24 Aug 2004 00:25:47 +0200
    
    

    On Monday 23 August 2004 20:27, ray canfield wrote:
    > >
    > > "169.254.0.0/16 - This is the "link local" block. It is allocated for
    > > communication between hosts on a single link. Hosts obtain these
    > > addresses by auto-configuration, such as when a DHCP server may not
    > > be found."
    >
    > but if some admin for the DNS servers above, accidently put an entry in
    > place in the zone files, the world would then see that resolution.
    > (or if someone broke in and played with that ip range)

    This would only affect reverse lookups. But all major routers should be
    configured not to route that subnet, so you won't get very far. Someone
    trying to fool your computer into thinking 169.254.10.5 is something
    important, like your bank, would have to be local to you (as in one hop away)
    in order to gain any advantage from it.

    But if someone has high level access to your local LAN, there are far easier
    ways to trick your computer that doesn't involve cracking IANA's name servers

    -- 
    Check the headers for your unsubscription address
    For additional commands send e-mail to suse-linux-e-help@suse.com
    Also check the archives at http://lists.suse.com
    Please read the FAQs: suse-linux-e-faq@suse.com
    

  • Next message: Tom Nielsen: "Re: [SLE] KDE's Remote Desktop...question"

    Relevant Pages

    • Re: Qs Regarding DNS
      ... >but via this method i am not sure that i have all the ips of site. ... since most DNS servers that service regular "anybody" Internet ... finding out all your hosts without brute force (i.e., ... I could throw in a good website's (like I don't know, Google ...
      (Security-Basics)
    • Re: DNS Forwarders - weird question
      ... > their DNS servers and all is well. ... Their hosts resolve off their DNS ... > requests to bigcompany's internal DNS servers, ...
      (microsoft.public.windows.server.dns)
    • Re: ~/.hosts patch
      ... One suggestion that was made was to make it an nss module so that it could be controlled by the admin. ... Seems like a bad idea to me, in terms of security. ... It's useful for cases where you want to add shortcuts to hosts as a user ...
      (freebsd-current)
    • Re: Intercept DNS request
      ... So to the rest of the internet; ... in the hosts file per pc, but that just seems like to much work. ... to specify the IP addresses of your ISPs DNS servers. ... Microsoft MVPs ...
      (microsoft.public.windows.server.sbs)
    • Re: dig and dns question
      ... are the same requests that slave dns servers use to mimmik zone ... configuration files across multiple dns servers incase if one goes down ... ('zone transfers') ... That command is not showing any other hosts. ...
      (comp.os.linux.misc)