07-22-2018 05:26 AM
The filtering of "Suspicious Responses" (e.g. private address space used by DNS Rebind attacks) is available, but disabled by default, in the OpenDNS Home product.
Wondering if it's enabled on the Family Shield product?
07-31-2018 11:24 AM
Why not simply test it out instead of asking here?
07-31-2018 01:56 PM
Well, I wasn't sure how to test, and didn't want to duplicate work that someone else may have already done.
So, I figured out how to test with this tool, and the filtering of "Suspicious Responses" does not appear to be enabled on the Family Shield product.
Any idea why this filtering is not enabled by default? In what cases would you ever want a public DNS server to return an address from a private address space?
Thanks.
08-01-2018 08:38 AM
"Any idea why this filtering is not enabled by default?"
I'm a user like you, but here my two cents and guesses:
It is not enabled by default, because any filtering is not part at all of a basic pure recursive DNS service. Such a service must return the information the authoritative nameservers provide. Consequently, this feature is available only as an option, via the OpenDNS Home dashboard where you can individually configure your recursive DNS to a certain extend. And FamilyShield is explicitly designed to just filter adult content and circumvention, not anything else.
"In what cases would you ever want a public DNS server to return an address from a private address space?"
In all cases where an owner of a domain name wants to point the A records to private RFC-1918 addresses and configures their authoritative DNS accordingly. There are more such authoritative entries of this sort than you can think of, and most of them are not intended for rebinding attacks but for "legit" purposes, although DNS was not intended to be used this way. But people use what is technically feasible.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide