<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.2" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Finally, a real solution to DNS rebinding attacks</title>
	<link>http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/</link>
	<description>Making the Internet safer and faster</description>
	<pubDate>Fri, 29 Aug 2008 08:15:51 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.2</generator>

	<item>
		<title>By: David Ulevitch</title>
		<link>http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-187261</link>
		<author>David Ulevitch</author>
		<pubDate>Mon, 28 Apr 2008 14:36:20 +0000</pubDate>
		<guid>http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-187261</guid>
		<description>Macmend,

If you add the domain of your WAN VPN or other trusted domain to your "typo exceptions" and your "whitelist domains" list then we will allow those answers to pass through as trusted and unchecked.

Terje,

Because of potential support issues like the one raised by macmend above we have decided to have the feature turned off by default for the time being.  Over time as we gain confidence that it doesn't break things, we might make it the default for new users. :-)</description>
		<content:encoded><![CDATA[<p>Macmend,</p>
<p>If you add the domain of your WAN VPN or other trusted domain to your &#8220;typo exceptions&#8221; and your &#8220;whitelist domains&#8221; list then we will allow those answers to pass through as trusted and unchecked.</p>
<p>Terje,</p>
<p>Because of potential support issues like the one raised by macmend above we have decided to have the feature turned off by default for the time being.  Over time as we gain confidence that it doesn&#8217;t break things, we might make it the default for new users. <img src='http://blog.opendns.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: macmend</title>
		<link>http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-187224</link>
		<author>macmend</author>
		<pubDate>Mon, 28 Apr 2008 12:47:59 +0000</pubDate>
		<guid>http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-187224</guid>
		<description>yes but how does this effect WAN VPNs, internal mail services, etc that rely on internal repsonses?</description>
		<content:encoded><![CDATA[<p>yes but how does this effect WAN VPNs, internal mail services, etc that rely on internal repsonses?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Terje Petersen</title>
		<link>http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-187223</link>
		<author>Terje Petersen</author>
		<pubDate>Mon, 28 Apr 2008 12:45:33 +0000</pubDate>
		<guid>http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-187223</guid>
		<description>Whilst it makes sence to have this as an op-in feature for existing OpenDNS users it would make sense to have this option turned on by default for any new accounts.</description>
		<content:encoded><![CDATA[<p>Whilst it makes sence to have this as an op-in feature for existing OpenDNS users it would make sense to have this option turned on by default for any new accounts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Glover</title>
		<link>http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-182255</link>
		<author>Tom Glover</author>
		<pubDate>Tue, 15 Apr 2008 10:47:10 +0000</pubDate>
		<guid>http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-182255</guid>
		<description>Very Good Idea,  I do believe that some of the fault is blamed on the browsers but, having a dns service that block this issue completely is brilliant and with nothing extra to install it is even better.</description>
		<content:encoded><![CDATA[<p>Very Good Idea,  I do believe that some of the fault is blamed on the browsers but, having a dns service that block this issue completely is brilliant and with nothing extra to install it is even better.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
