[dns-operations] Destination-adjacent source address spoofed DNS queries

John Kristoff jtk at dataplane.org
Wed Mar 6 14:42:06 UTC 2024

On Wed, 06 Mar 2024 10:51:37 +0100
Florian Weimer <fw at deneb.enyo.de> wrote:

> I'm seeing these packets as well, and I'm worried for a completely
> different reason: They strongly suggest that the ISPs I use are not
> capable of filtering their (provider-owned ) address space in source
> addresses at their network borders.

Hi Florian, long time no chat.  Thanks as always for your insight.  I'm
embarrassed we didn't think of this.  We made an update to the end of
the article and attributed the idea to you.


