FC: Microsoft websites blacked out -- but what happened?

Marco Anglesio mpa at the-wire.com
Thu Jan 25 13:34:20 PST 2001


On Thu, 25 Jan 2001, jf noonan wrote:
> That would be a pretty unusual thing to do with your *public*
> resolvers, to firewall/NAT them. It's quite unclear to me what
> the point would be.

Why not? You only have to let port 53 in for DNS services. Putting any machine outside a firewall is equivalent to saying that they should be attacked. If you're Microsoft, it's equivalent to begging for them to be attacked. The reflexive distaste or even hate for Microsoft in the hacker community cannot be underestimated.


> If you can believe M$'s explanation of the problem, then a
> single router misconfiguration caused this problem. That is

Aha. Yes, I read that today. It doesn't violate 1034 or 1035 (which merely specify that name service be redundant) but it certainly violates good sense. Perhaps it's symptomatic of the rather insular mentality at MSFT - it's not like Microsoft has lax hiring standards. A shame all around.

Marco

,--------------------------------------------------------------------------.
> | We know what causes violence: poverty, <
> Marco Anglesio | discrimination, the failure of the <
> mpa at the-wire.com | educational system. It's not the genes <
> http://www.the-wire.com/~mpa | that cause violence in our society. <
> | --Paul Billings <
`--------------------------------------------------------------------------'



More information about the lbo-talk mailing list