IN TXT & NULL trash records

Daisuke HIGASHI daisuke.higashi at
Thu Nov 22 14:12:51 UTC 2018


Rate-limiting queries per source IP with specific query type (NULL/TXT) and
long qname (e.g. 20 byte or longer). That should be possible using iptables
hashlimit module and dns-extension [1].
That will make DNS-tunnel VPN useless while accepting legitimate TXT/NULL

