Re: named 8.3.2-T1B vulnerable?

From: Alessandro de Manzano (adm@unixmania.net)
Date: 06/30/02


Date: Sun, 30 Jun 2002 22:58:43 +0200
From: Alessandro de Manzano <adm@unixmania.net>
To: Doug Barton <DougB@FreeBSD.org>

On Sun, Jun 30, 2002 at 01:37:03PM -0700, Doug Barton wrote:

> Correct. There is currently a make.conf option for NO_BIND. In

yes, I knew it but I totally forgot about it ;)

> addition, some of us are working on a more thorough solution which will
> add some magic to the bsd.*.mk files so that you can put
> PORT_REPLACES_BASE_FOO in your /etc/make.conf, and it will automatically
> imply NO_FOO as well. Currently I'm testing a final buildworld for the

yup, should be useful :-)

> > More, I'll get an entry in the installed packages database for BIND
> > 8.3.3 that is "dangerous", since if I'll ever pkg_delete it I'll lost
> > the real/overwritten BIND...
>
> Yep. One of the things I'm adding to my little patch is to change the
> name of the port from foo-version to foo-system-version when installing
> to give you a clue as to what's about to happen. BUT, you are absolutely

IMHO the current system of -DSOMETHING is good, maybe just a couple of
suggestions: use a standard name (PORT_REPLACES_BASE_xxx as you said),
maybe it's already this way, I don't know :)) and/or a dialog(1) menu to
choose whether overwrite base components or not :)
Sometimes people 'forgot' to read into Makefiles to look for every
possible -D symbols..

> right in saying that this option is dangerous. However, there are lots
> of ways to shoot yourself in the foot here... it's up to you to find a
> better target. :) Also, the system will still run without BIND, unless

yes, of course :) you're right

> of course you're using that particular system as a name server. I have

a couple boxes of mine are actually public name servers, so I'll
absolutely upgrade them to 8.3.3 tomorrow morning.
This evening I upgraded my home box in this way to learn :)

> been using the "port overwrites base" stuff at Yahoo! for almost a year,
> and we haven't had any catastrophes yet.
>
> Hope this helps,

Yes, defintely! Thanks a lot ! :-)

-- 
bye!
Ale
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • [UNIX] Hardening the BIND DNS Server
    ... Hardening the BIND DNS Server ... Your Domain Name Service is the road sign to your systems on the Internet. ...
    (Securiteam)
  • Re: PDC Is not replicating !!
    ... Manage to change the Driver issue to boot the server. ... Starting test: Connectivity ... Starting test: Replications ... LDAP Bind. ...
    (microsoft.public.win2000.active_directory)
  • Re: Mail server security - best practices?
    ... Both BIND and qmail are pretty secure, ... and mail on a server that's 'half-internal' in that you seem not to ... I still employ IMAP-SSL on the private server, ...
    (comp.unix.bsd.openbsd.misc)
  • Re: DNS Poisoning, pharming, pollution
    ... running Windows 2003 and have the "secure cache against pollution" setting ... the next thing to look for would be a malicious program on the server. ... >> Every server is configured with our ISP's DNS resolvers as forwarders. ... but I don't think we're running BIND. ...
    (microsoft.public.windows.server.dns)
  • Re: bind hack?
    ... He writes BIND 9. ... rfcs as documentation and therefor basis for design it is a shitload ... dns server software developed, tested and finally deployed. ... security dilemma since this monoculture defines the standard. ...
    (FreeBSD-Security)