RFC 1535: A Security Problem and Proposed Correction With Widely Deployed DNS Software
In plain English — editorial summary, not part of the RFC
This document discusses a flaw in some of the currently distributed name resolver clients. The flaw exposes a security weakness related to the search heuristic invoked by these same resolvers when users provide a partial domain name, and which is easy to exploit. This document points out the flaw, a case in point, and a solution. This memo provides information for the Internet community. It does not specify an Internet standard.
Document record
- Document ID
- RFC1535
- Published
- October 1993
- Authors
- E. Gavron
- Status
- INFORMATIONAL
- Stream
- Legacy
- Area
- —
- Pages
- 5
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 1538Advanced SNA/IP : A Simple SNA Transport ProtocolCurrent
October 1993
- RFC 1637DNS NSAP Resource RecordsObsoleted
June 1994
- RFC 1706DNS NSAP Resource RecordsUpdated
October 1994
- RFC 1912Common DNS Operational and Configuration ErrorsCurrent
February 1996
- RFC 2052A DNS RR for specifying the location of services (DNS SRV)Obsoleted
October 1996
- RFC 2230Key Exchange Delegation Record for the DNSCurrent
November 1997
- RFC 2517Building Directories from DNS: Experiences from WWWSeekerCurrent
February 1999
- RFC 3130Notes from the State-Of-The-Technology: DNSSECCurrent
June 2001
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?