>> Anyone doing anything more complex than that really should be
>> running their own caching nameserver, for a variety of reasons
>> besides this anyway.
> Of course, what's to stop the botnet controllers from installing their
> own caching resolvers on the 0wned machines?

In fact some already do that. I don't know for sure but I suspect
reasons are Verisign sitefinder or alike that a few ISPs setup locally.

