<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Finally, a real solution to DNS rebinding attacks</title>
	<atom:link href="http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/</link>
	<description>Making the Internet safer and faster</description>
	<lastBuildDate>Tue, 07 Feb 2012 20:12:30 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Internet Evolution - Jart Armin - Router Hacking Takes Stage at Black Hat</title>
		<link>http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-366328</link>
		<dc:creator>Internet Evolution - Jart Armin - Router Hacking Takes Stage at Black Hat</dc:creator>
		<pubDate>Thu, 29 Jul 2010 19:13:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-366328</guid>
		<description></description>
		<content:encoded><![CDATA[<p>[...] Fortunately, Ulevitch wrote, “OpenDNS has secured users from DNS rebinding attacks for a long time.” [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: OpenDNS Blog &#187; Calling Craig Heffner</title>
		<link>http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-365953</link>
		<dc:creator>OpenDNS Blog &#187; Calling Craig Heffner</dc:creator>
		<pubDate>Tue, 27 Jul 2010 18:33:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-365953</guid>
		<description>[...] it to address. The only information we have is that this deals with DNS Rebinding. Fortunately, OpenDNS has secured users from DNS rebinding attacks for a long time. But we don&#8217;t know what&#8217;s different about Craig&#8217;s new rebinding [...]</description>
		<content:encoded><![CDATA[<p>[...] it to address. The only information we have is that this deals with DNS Rebinding. Fortunately, OpenDNS has secured users from DNS rebinding attacks for a long time. But we don&#8217;t know what&#8217;s different about Craig&#8217;s new rebinding [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Ulevitch</title>
		<link>http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-187261</link>
		<dc:creator>David Ulevitch</dc:creator>
		<pubDate>Mon, 28 Apr 2008 14:36:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-187261</guid>
		<description>Macmend,

If you add the domain of your WAN VPN or other trusted domain to your &quot;typo exceptions&quot; and your &quot;whitelist domains&quot; list then we will allow those answers to pass through as trusted and unchecked.

Terje,

Because of potential support issues like the one raised by macmend above we have decided to have the feature turned off by default for the time being.  Over time as we gain confidence that it doesn&#039;t break things, we might make it the default for new users. :-)</description>
		<content:encoded><![CDATA[<p>Macmend,</p>
<p>If you add the domain of your WAN VPN or other trusted domain to your &#8220;typo exceptions&#8221; and your &#8220;whitelist domains&#8221; list then we will allow those answers to pass through as trusted and unchecked.</p>
<p>Terje,</p>
<p>Because of potential support issues like the one raised by macmend above we have decided to have the feature turned off by default for the time being.  Over time as we gain confidence that it doesn&#8217;t break things, we might make it the default for new users. <img src='http://blog.opendns.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: macmend</title>
		<link>http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-187224</link>
		<dc:creator>macmend</dc:creator>
		<pubDate>Mon, 28 Apr 2008 12:47:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-187224</guid>
		<description>yes but how does this effect WAN VPNs, internal mail services, etc that rely on internal repsonses?</description>
		<content:encoded><![CDATA[<p>yes but how does this effect WAN VPNs, internal mail services, etc that rely on internal repsonses?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Terje Petersen</title>
		<link>http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-187223</link>
		<dc:creator>Terje Petersen</dc:creator>
		<pubDate>Mon, 28 Apr 2008 12:45:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-187223</guid>
		<description>Whilst it makes sence to have this as an op-in feature for existing OpenDNS users it would make sense to have this option turned on by default for any new accounts.</description>
		<content:encoded><![CDATA[<p>Whilst it makes sence to have this as an op-in feature for existing OpenDNS users it would make sense to have this option turned on by default for any new accounts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Glover</title>
		<link>http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-182255</link>
		<dc:creator>Tom Glover</dc:creator>
		<pubDate>Tue, 15 Apr 2008 10:47:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.opendns.com/2008/04/14/finally-a-real-solution-to-dns-rebinding-attacks/#comment-182255</guid>
		<description>Very Good Idea,  I do believe that some of the fault is blamed on the browsers but, having a dns service that block this issue completely is brilliant and with nothing extra to install it is even better.</description>
		<content:encoded><![CDATA[<p>Very Good Idea,  I do believe that some of the fault is blamed on the browsers but, having a dns service that block this issue completely is brilliant and with nothing extra to install it is even better.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

