|
|
|
|
|
by rocqua
2982 days ago
|
|
Yes, you can set a short TTL on your NS record, but that would not keep this attack from hijacking your site.
This attack intercepts the clients DNS lookup, so the DNS a browser is talking to is ill-behaved.
No amount of correct setup here will work because the ill-behaved DNS server will just replace your setup with whatever that server wants. There is no strong defense against this as a website. With an app the solution would be certificate pinning. You could try HPKP but that comes with a host of issues and I think it is being deprecated. |
|
I think unless a TLD registrar gets hijacked that mitigates the attack on your own DNS after the NS TTL