This is not a “newly discovered vulnerability. This was presented at DNS OARC 21 by Florian Maury in 2015 https://indico.dns-oarc.net/event/21/contributions/301/attachments/272/492/s..., and also details the fixes applied to resolvers at the time. As Florian also points out the generic vulnerability of unbounded work flows was identified by Dr Paul Mockapetris in RFC1034 in 1987. thanks, Geoff
On 21 May 2020, at 12:43 am, Mirjam Kuehne <mir@ripe.net> wrote:
Dear colleagues,
This article by Petr Špaček of CZ.NIC describes a newly discovered DNS protocol vulnerability that affects all recursive DNS resolvers. NXNSAttack allows the execution of random subdomain attacks using the DNS delegation mechanism, resulting in a big packet amplification factor.
Please read more about this on RIPE Labs:
https://labs.ripe.net/Members/petr_spacek/nxnsattack-upgrade-resolvers-to-st...
Kind regards, Mirjam Kühne RIPE NCC