Re: ProFTPd and reverse DNS

From: Michael S. Fischer (michael@dynamine.net)
Date: 09/08/01


Date: Fri, 7 Sep 2001 17:16:14 -0700
From: "Michael S. Fischer" <michael@dynamine.net>
To: "Matthew S . Hallacy" <poptix@techmonkeys.org>
Subject: Re: ProFTPd and reverse DNS
Message-ID: <20010907171614.A23062@dynamine.net>

On Fri, Sep 07, 2001 at 03:38:27PM -0600, Matthew S . Hallacy wrote:

> Recently while browsing through security logs I noticed that quite a
> few of the hosts connecting to the machine did not resolve, I've
> checked into it, and apparently ProFTPd does not check forward to
> reverse DNS mappings, and only resolves the IP address connecting.
> This could easily lead to an attacker hiding his real hostname from
> logfiles, or an attacker slipping through ACL's by modifying their
> hostname. For the time being I recommend that the option
> 'UseReverseDNS' be disabled in the configuration file until this is
> fixed.

Another potentially useful workaround is to configure ProFTPd to run out
of inetd, using TCP Wrappers to enforce paranoid DNS checks. This way
you can have your cake and eat it too.

Running ProFTPd out of inetd, while slower than running it in standalone
mode without DNS lookups activated, is still going to be faster than
running it in standalone mode with DNS lookups activated.

-- 
Michael S. Fischer / michael at dynamine.net / +1 650-533-4684
Lead Hacketeer, Dynamine Consulting, Silicon Valley, CA



Relevant Pages

  • Re: [Full-disclosure] Reverse dns
    ... Reverse DNS lookups are entirely optional; ... If you believe reverse DNS is a security or performance issue for your ... filter out problem hosts. ...
    (Full-Disclosure)
  • Re: SMTP and Sat ADSL
    ... Cris Hanna, SBS-MVP ... Secondary DNS: 193.xxx.xxx.20 ... Now I assume I need to get them to give me a Static IP, ideally 217.xxx.xxx.202 and enable reverse DNS on it rather than on the Gateway IP ... Who created those DNS records and on whose server do they reside??? ...
    (microsoft.public.backoffice.smallbiz)
  • Re: ProFTPd and reverse DNS
    ... Subject: ProFTPd and reverse DNS ... >> few of the hosts connecting to the machine did not resolve, ... >> reverse DNS mappings, and only resolves the IP address connecting. ...
    (Bugtraq)
  • Re: Reverse DNS Issue
    ... > We currently host our own external DNS server with the ... > cannot do a Reverse DNS lookup on our domain. ... etc but can only have ONE PTR record ...
    (microsoft.public.win2000.dns)
  • Re: Cannot send mail out after default installation
    ... Asked IP owner to add a PTR record to their DNS server (RDNS) ... of your mail serverhave no reverse DNS entries/* (if you see ... It is strongly urged that you have them, as many mailservers will ...
    (microsoft.public.windows.server.sbs)