Caching behaviour of InetAddress

Florian Weimer fw at deneb.enyo.de
Mon Feb 18 09:56:03 PST 2008


* Alan Bateman:

> Search for a ~1996 paper on DNS spoofing attacks from Princeton
> University as that gives useful background on this topic and is the
> original reason for the caching.

That paper is probably out of date by now.  Interaction of expiry and
poisoning hasn't been fully understood back then.

> When a security manager is set then it caches forever and getByName
> will always return the same address.

This is probably related to DNS pinning/anti-pinning attacks, not to
cache poisoning.



More information about the net-dev mailing list