sednet wrote:
It should be easy enough to hack bind so it just drops these queries. What's the legitimate use of ANY queries anyway?
I see some clients that do ANY queries for my nameservers' hostnames to save themselves the trouble of doing separate AAAA and A queries. I don't know what the result of dropping those queries would be, but it might not be good.
Edit: By the way, I looked up two of the Linode /24s I'm on in the Open Recursive Project. One didn't have any results, the other had 9. Of them, 3-4 were real open resolvers; the others were apparently authoritative servers that unhelpfully returned . NS in response to strange queries.
Edit: Also by the way, SoftLayer/The Planet, where Linode colos in Dallas, is one of the top ASNs for open resolvers. Linode is a -- presumably small -- part of that.