Re: BIND/DNS Version check

From: Nexus (nexus@patrol.i-way.co.uk)
Date: 04/11/03

  • Next message: Sebastian Jaenicke: "Re: BIND/DNS Version check"
    From: "Nexus" <nexus@patrol.i-way.co.uk>
    To: "Asim Shaikh" <wezmaster@hotmail.com>, <pen-test@securityfocus.com>
    Date: Fri, 11 Apr 2003 18:43:02 +0100
    
    

    ----- Original Message -----
    From: "Asim Shaikh" <wezmaster@hotmail.com>

    [snip]

    > I would like to know if there is any tool out there which can check for
    > version of BIND/DNS running on the server.. or a scanner which can scan
    for
    > the possible BIND/DNS vulnerabilites..
    >
    > I would like to know tools available on both paltform *nix and also Win32.

    You can use nslookup or dig, one or both of which will usually be on either
    Win32 or *NIX.
    nslookup -q=txt -class=chaos version.bind ns0.example.com or
    dig @ns0.example.com -c chaos version.bind txt
    and look at http://www.isc.org/products/BIND/bind-security.html for any
    results you get.

    Cheers.

    --------------------------------------------------------------
    Costs are climbing and complaints are rising
    as SPAM overloads your e-mail servers and Inboxes
    SurfControl E-mail Filter puts the brakes on spam & viruses
    and gives you the reports to prove it.
    http://www.securityfocus.com/SurfControl-pen-test2
    Download a free trial and see just
    what's going in and out of your organization.
    --------------------------------------------------------------


  • Next message: Sebastian Jaenicke: "Re: BIND/DNS Version check"

    Relevant Pages

    • Re: Reverse map delay on OpenSSH 3.4 on FreeBSD
      ... > Try looking up your IP against what the server is using, ... > /etc/resolv.conf to get a list, then for each do (use dig, nslookup ... map the IP. ...
      (comp.security.ssh)
    • Re: Reverse map delay on OpenSSH 3.4 on FreeBSD
      ... > Try looking up your IP against what the server is using, ... > /etc/resolv.conf to get a list, then for each do (use dig, nslookup ... map the IP. ...
      (comp.security.ssh)
    • Re: naive bind question
      ... I looked at dig and also nslookup. ... Does this mean that I'm using 127.0.0.1 as my name server? ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
      (Debian-User)
    • Re: ping computer returns wrong IP
      ... >use dig or netdig or nslookup to see ... Then check that server. ...
      (microsoft.public.win2000.dns)
    • Re: Cannot Resolve Names Outside Windows Domain
      ... As I posted previously, at your suggestion, I tried the nslookup command outside of the windows domain. ... The result show nslookup is trying to use the windows domain 192.168.1.2 even when that name server is unavailable. ... Presumably if nslookup resolved to the IPS name server, the laptop could resove names and would allow internet browsing? ... you wrote that you have an assigned DNS server that you can ping. ...
      (microsoft.public.windowsxp.network_web)