Hacker News new | past | comments | ask | show | jobs | submit login

Sounds similar to AXFR queries, which it is best practice to disable. It's not advisable in general to provide information about hosts that the querier didn't request specifically and individually.

"A remote unauthenticated user may observe internal network structure, learning information useful for other directed attacks."

https://us-cert.cisa.gov/ncas/alerts/TA15-103A




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: