top | item 41573486

(no title)

X-Istence | 1 year ago

Not resolving 127.0.0.1 or RFC1918 addresses or even ULA for IPv6 is done to avoid DNS rebinding attacks. For most end users that is probably the correct move.

discuss

order

lxgr|1 year ago

My home router even seems to inspect any UDP/53 traffic and redact any responses containing local/private A entries, so not even switching to a public resolver bypasses the protection.

I agree that it’s usually the right behavior.

cj|1 year ago

Interesting. I hadn’t considered it might be a security feature of his router!