RE: Pubstro rash

From: Joshua Berry (jberry_at_PENSON.COM)
Date: 03/18/05

  • Next message: Ben Blakely: "Netscreen 5XT SSH Traffic"
    Date: Fri, 18 Mar 2005 09:30:51 -0600
    To: "Jeff Kell" <jeff-kell@utc.edu>, <alexandre.skyrme@ciphersec.com.br>
    
    

    I have never had a DNS query that had a response that was over 512
    bytes. For that reason I disable all inbound DNS over 53/tcp. I have
    been using this configuration for years and even run my own DNS servers
    and have see absolutely no problems.

    -----Original Message-----
    From: Jeff Kell [mailto:jeff-kell@utc.edu]
    Sent: Thursday, March 17, 2005 6:07 PM
    To: alexandre.skyrme@ciphersec.com.br
    Cc: incidents@securityfocus.com; gillettdavid@fhda.edu
    Subject: Re: Pubstro rash

    Alexandre Skyrme wrote:
    > Greetings David,
    >
    > Just a thought about your third comment...
    >
    > As far as I'm concerned DNS just uses 53/TCP to do zone transfers. In
    case
    > your workstations are on a different network than your DNS servers it
    should
    > probably be safe to block incoming TCP connections to that network on
    such
    > port.
    >
    > Tipically zone transfers would only be used by secondary servers to
    update
    > their own zones from its primary server.

    RFC1035 allows 512 bytes for a DNS response (53) but they may now be
    longer, according to RFC2671 and others. If the DNS query fails or is
    "truncated", the query may be repeated over TCP.

    So, 53/tcp is NOT just for zone transfers.

    Jeff


  • Next message: Ben Blakely: "Netscreen 5XT SSH Traffic"

    Relevant Pages

    • Re: Dual NIC vs Single NIC
      ... Thank you for helping me to correct the misunderstand of DNS query process. ... Thank you again for your supplement about the client DNS cache issue. ... | server rather than using locally cached information may slow things down. ...
      (microsoft.public.windows.server.sbs)
    • Re: Cant resolve mx records
      ... 828731 An External DNS Query May Cause an Error Message in Windows Server ... 832223 Some DNS Name Queries Are Unsuccessful After You Upgrade Your DNS ... What type of firewall and/or router separates the DNS servers from the ...
      (microsoft.public.win2000.dns)
    • Re: I change DNS primary and it doesnt update DNS secondary
      ... > DNS Primary and DNS Secondary, ... are you allowing zone transfers to all the private IP addresses on ... Not good if these are public DNS servers because the NS records must have ... To help speed up the zone updates on the secondary, I suggest you use Notify ...
      (microsoft.public.win2000.dns)
    • Re: Confusing problem..Please help.
      ... I have a caching DNS server running on my server. ... whoever actually controls the IP address space sets up reverse DNS -- ... Recall that for an ordinary domain name, such as "public.com", its DNS address is resolved first by asking the hardcoded list of root domain servers, ".". ... They will not respond directly, but refer you to the domain servers that are authoritative for ".com", and they will refer you to the authoritative servers for ".public.com", which, presumably, will respond to the DNS query. ...
      (comp.mail.misc)
    • Changing machine startup sequence in the registry
      ... Currently the following procedure takes place during machine startup on XP/2003 clients in a domain: ... DNS servers, default gateway, etc. ... DNS query for domain controllers. ...
      (microsoft.public.windows.server.security)