Re: DNS Question

From: Tim Wilde (twilde@dyndns.org)
Date: 04/22/02


Date: Mon, 22 Apr 2002 12:04:31 -0400 (EDT)
From: Tim Wilde <twilde@dyndns.org>
To: Jim Flowers <jflowers@ezo.net>

On Mon, 22 Apr 2002, Jim Flowers wrote:

> You don't say what version but assuming 8.x.x there are a number of options
> to help. Read Chapter 10 of the DNA & BIND book. Particularly, you can
> configure your dns to be useful as a resolver to only your trusted addresses
> with option allow-query {trusted-addresses;} while at the same time allowing
> everyone access to your authoritative zones with an allow-query {any;} entry
> in each of your authoritative zone files.

The allow-recursion { }; statement within the options { }; block is more
correct to use to limit recursion, I'm pretty sure it's available in BIND
8, and it definitely is in BIND 9. DNS & BIND is a very good resource, as
is the BIND ARM that ships in the doc/ dir of the BIND distribution.

Tim Wilde

-- 
Tim Wilde
twilde@dyndns.org
Systems Administrator
Dynamic DNS Network Services
http://www.dyndns.org/
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • [NEWS] BIND 9 DNS Cache Poisoning
    ... BIND 9 DNS Cache Poisoning ... source UDP port and DNS transaction ID can be effectively predicted. ... address of the target name server), and the destination UDP port (53 the ...
    (Securiteam)
  • [UNIX] Multiple Remote Vulnerabilities in BIND4 and BIND8
    ... ISS X-Force has discovered several serious vulnerabilities in the Berkeley ... Internet Name Domain Server (BIND). ... majority of DNS servers on the Internet. ... deployed recursive DNS servers on the Internet. ...
    (Securiteam)
  • Re: DNS Manipulation via IPTables or other means?
    ... You might use the BIND view functionality ... I thought I could alter DNS responses ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic ...
    (Security-Basics)
  • Re: DNS Manipulation via IPTables or other means?
    ... Not sure about iptables. ... I nwhat way is BIND not scalable -- ... I thought I could alter DNS responses ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ...
    (Security-Basics)
  • Re: your mail
    ... I even bought DNS and BIND from O'riley. ... For debugging Bind9, start by getting Bind to log a lot of stuff. ... continually on a busy production server. ...
    (freebsd-questions)