Skip to content

DNS cache snooping attack #14000

Answered by rgacogne
abdrabo asked this question in Q&A
Discussion options

You must be logged in to vote

Since 5.0.0, a new setting has been introduced and queries with the RD bit clear (so cache-only, not asking for recursion) are refused by default: https://docs.powerdns.com/recursor/settings.html#allow-no-rd
We still don't consider the previous behaviour a vulnerability, but "security" tools reporting it as such made it annoying enough for everyone that it made sense to change the default. The discussion can be found here, if you are interested: #13386

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by abdrabo
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
2 participants