Re: Pubstro rash

From: Jeff Kell (jeff-kell_at_utc.edu)
Date: 03/18/05

  • Next message: Jonathan Nichols: "Re: Netscreen 5XT SSH Traffic"
    Date: Fri, 18 Mar 2005 10:59:42 -0500
    To: Joshua Berry <jberry@PENSON.COM>
    
    

    Joshua Berry wrote:
    > I have never had a DNS query that had a response that was over 512
    > bytes. For that reason I disable all inbound DNS over 53/tcp. I have
    > been using this configuration for years and even run my own DNS servers
    > and have see absolutely no problems.

    If you aren't authoritative over a zone that requires large response
    records, you'll never receive one. But you may very well send some
    queries out yourself (you allow 53/tcp outbound statefully?)

    But in more general terms:

    http://www.maradns.org/dnstcp_security.html
    http://support.microsoft.com/default.aspx?scid=kb;en-us;828263
    http://support.microsoft.com/kb/832223
    http://www.certcities.com/editorial/columns/print.asp?EditorialsID=144
    https://lists.netfilter.org/pipermail/netfilter/2002-January/029765.html
    http://www.faqs.org/rfcs/rfc3226.html

    (Among others).

    Jeff


  • Next message: Jonathan Nichols: "Re: Netscreen 5XT SSH Traffic"

    Relevant Pages

    • Re: W2k DNS limitationload
      ... responsibility of the resolver to determine the kind of response it ... added sometime after W2k release in order to harden the DNS server ... >> William Stacey, MVP ...
      (microsoft.public.windows.server.dns)
    • Re: Local machine - DNS issues?
      ... Response - DNS: 0x2623:Std Qry Resp. ... The request on the bad machine isn't a DNS request but a NETBIOS request. ... Stop the network traces and compare the results. ...
      (microsoft.public.win2000.dns)
    • Re: Local machine - DNS issues?
      ... Response - DNS: 0x2623:Std Qry Resp. ... The request on the bad machine isn't a DNS request but a NETBIOS request. ... Stop the network traces and compare the results. ...
      (microsoft.public.win2000.networking)
    • Re: W2k DNS limitationload
      ... The request and the reply would be best (i.e. the ... William Stacey, MVP ... The application needs a recursive response from the DNS server ...
      (microsoft.public.windows.server.dns)
    • Re: Reverse DNS with Multiple Virtual Hosts
      ... Thanks for the response and detailed information, ... > public DNS, and it would be pointless besides simply because applications ... > reverse name for the sender's IP. ... > But if the receiving mail server is insisting that the reverse lookup map ...
      (microsoft.public.windows.server.dns)