Rob Thomas robt at cymru.com
Mon Feb 27 05:15:36 UTC 2006

Hi, team.

] the only hint of a solution i've seen in all this so far is
] automated shunning of known-open-recursive + known-recent-abused
] name servers...

A variant of that theme would be to report these name servers
through one of several extant mechanisms.  This has shown
promise already.

I do agree that a feed of this information is useful, and could
be used by folks both for alerting and for filtering.  I'd
prefer to alert folks first in all cases, even during an attack.

