Re: Bind problems

From: Michael Richards (michael@fastmail.ca)
Date: 02/22/01


To: Cy.Schubert@uumail.gov.bc.ca
From: "Michael Richards" <michael@fastmail.ca>
Date: Thu, 22 Feb 2001 15:37:58 -0500 (EST)


Hi.

Within minutes of discovering that the version of bind was
compromised, it was shut down and an onsite person booted the system
from a disk and ran tripwire. Nothing odd. I've been monitoring via
the firewall and paying close attention to that machine and there is
nothing out of the ordinary going on with it. I have a feeling that
people were trying a linux specific exploit and that was merely
causing bind to crash.

-Michael

> I wouldn't be surprised if your system has already been hacked.
> 8.2.3-REL has fixed all known (to ISC) security holes. All
> previous versions of BIND are vulnerable. If I (taking my
> manager's hat off and putting my security officer's hat on) were
> you I'd do the prudent thing, which is to verify the system was
> not already hacked or otherwise consider the system suspect until
> I can prove it otherwise.

_________________________________________________________________
     http://fastmail.ca/ - Fast Free Web Email for Canadians

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: Root cant delete files
    ... > I have included the "poorly documented" install script ... > Does anyone know of any security holes in bind 8.2.3? ... before security holes come up in *any* version - and then, ...
    (Focus-Linux)
  • Re: Bind problems
    ... > Since the big BIND vulnerability, I checked all my versions of BIND ... 8.2.3-REL has fixed all known security holes. ... putting my security officer's hat on) were you I'd do the prudent ...
    (FreeBSD-Security)
  • Re: Bastille
    ... > Had the sendmail any security holes recently? ... > Linux do you recommend instead of BIND? ... of course we all are using bind and Windows;-) ...
    (comp.security.unix)
  • Re: Bind 9.2.4-1 very slow in resolving uncached querres
    ... It is a damn major stupid dumbass bug in bind, ... I mean, hardcoding a ... "One disk to rule them all, ...
    (Debian-User)
  • Re: Bind problems
    ... you may have been running -u bind -g bind and that works to keep the ... On Thu, 22 Feb 2001, Michael Richards wrote: ... I have a feeling that ... >> manager's hat off and putting my security officer's hat on) were ...
    (FreeBSD-Security)

Quantcast