Re: Bind: unapproved query (version.bind) Script kiddies?

From: Kris Kennaway (kris@obsecurity.org)
Date: 01/31/01


Date: Tue, 30 Jan 2001 18:42:16 -0800
From: Kris Kennaway <kris@obsecurity.org>
To: David La Croix <dlacroix@cowpie.acm.vt.edu>


On Tue, Jan 30, 2001 at 04:45:04PM -0600, David La Croix wrote:
> I just noticed the following in my logfiles: (/var/log/messages)
>
> it was running Bind 8.2.2-
>
> Jan 26 22:37:43 mildred named[41908]: unapproved query from [208.44.147.11].1584
> for "version.bind"
> [repeat 23 more times from the same IP]

Yes, they're querying you for the version of BIND you're
running. Since 8.2.2 is vulnerable I suggest you update ASAP.

Kris



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message