Re: Unapproved updates

From: Scott Gifford (sgifford@suspectclass.com)
Date: 11/16/01


To: "Fab Siciliano" <fsiciliano@optiumcorp.com>
Subject: Re: Unapproved updates
From: Scott Gifford <sgifford@suspectclass.com>
Date: 16 Nov 2001 12:17:50 -0500
Message-ID: <lyd72iprcx.fsf@gfn.org>


"Fab Siciliano" <fsiciliano@optiumcorp.com> writes:

> Hey everybody,
>
> I just recently started seeing all these unapproved updates hitting my
> dns server in /var/log/messages. Is this a security risk? Do I need to
> allow updates if it's a secondary dns server? If I don't allow updates,
> then there would be no point to direct users to it...right? Because it
> wouldn't be caching other hosts' info. Am I right on this or WAY OFF?
> Thanks,

By "secondary", do you mean a caching-only server, or a slave server
for one or more DNS zones?

If it's a caching-only server, you shouldn't be accepting updates at
all. DNS doesn't use updates to notify name servers of changes in
normal use; it uses timeouts and asking for the data again.

If it's a slave server for one or more DNS zones, it should accept
some updates. You'll need to talk to the people operating the master
server it's receiving updates from to know what to expect; generally
you'll allow updates to particular zones from particular IP
addresses. Newer versions of some DNS software (notably BIND) have
more complex authentication mechanisms, although as far as I know they
aren't used all that widely.

Good luck,

----ScottG.



Relevant Pages

  • Re: DNS not dynamically updating clients
    ... I already see 1 NT40 workstation we had left register on our DNS. ... I just have 1 more question, If I wanted to make dynamic updates work ... we upgrade to AD can I just go ahead and rename our Primary DNS server to ... DNS domain of the clients ...
    (microsoft.public.win2000.dns)
  • Re: Cannot connect to lan on SBS 2003 after Windows Update this We
    ... I, removed/unistalled the updates from the weekend, disabled Remoteaccess, ... Have you checked the DNS settings on the SBS server and make sure the ... You're using POP3 connector, ...
    (microsoft.public.windows.server.sbs)
  • Re: Dynamic DNS [WildPacket]
    ... I configured the zone to allow secure updates. ... >> I installed and activated a new DHCP server on my member server and I ... >> The following DNS server that is authoritative for the DNS domain ...
    (microsoft.public.windows.server.dns)
  • RE: path to client not found
    ... did not configure SBS DNS server for reverse DNS lookup. ... I will be here waiting for your updates. ... |> | Ethernet adapter Server Local Area Connection: ...
    (microsoft.public.windows.server.sbs)
  • Re: Domain authentication problem
    ... configuration of Dynamic DNS, hence updates now enabled. ... restarting DHCP server restores this as default after I ... modern Windows versions where clients can register their own IP ...
    (microsoft.public.windows.server.networking)