Re: DNS ACL ?

From: John Nemeth (jnemeth_at_victoria.tc.ca)
Date: 11/12/05

  • Next message: Stephen J. Smoogen: "Re: DNS ACL ?"
    Date: Sat, 12 Nov 2005 13:09:43 -0800
    To: John Hally <JHally@epnet.com>, "'pen-test@securityfocus.com'" <pen-test@securityfocus.com>
    
    

    On Apr 3, 3:10am, John Hally wrote:
    }
    } I need a sanity check regarding DNS ACLs. For external facing DNS servers
    } you need to allow only udp/53 inbound, correct? I know tcp/53 is used for

         No.

    } zone transfers and requests/replies greater than a certain size, but they
    } shouldn't typically happen for general dns queries correct?

         Depends on the size of the query. Which in turn depends on how
    your DNS is setup (i.e. do you have hosts with a large number of A
    records, do you have a number of MX records {queries for these usually
    return the A records as 'Additional Info'}, or have AAAA records?).
    Also, don't forget about your secondaries if they happen to be
    offsite.

    }-- End of excerpt from John Hally

    ------------------------------------------------------------------------------
    Audit your website security with Acunetix Web Vulnerability Scanner:

    Hackers are concentrating their efforts on attacking applications on your
    website. Up to 75% of cyber attacks are launched on shopping carts, forms,
    login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
    futile against web application hacking. Check your website for vulnerabilities
    to SQL injection, Cross site scripting and other web attacks before hackers do!
    Download Trial at:

    http://www.securityfocus.com/sponsor/pen-test_050831
    -------------------------------------------------------------------------------


  • Next message: Stephen J. Smoogen: "Re: DNS ACL ?"

    Relevant Pages

    • FW: DNS ACL ?
      ... Subject: DNS ACL? ... queries are sent to the DNS server IP address, ... > Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping ...
      (Pen-Test)
    • RE: DNS ACL ?
      ... forget to allow the DNS servers outbound reply. ... Subject: DNS ACL? ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, forms, ...
      (Pen-Test)
    • RE: DNS ACL ?
      ... 53/UDP is used for DNS Queries and 53/TCP is used for Zone ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, ...
      (Pen-Test)
    • Re: DNS ACL ?
      ... Exchange use TCP 53 for DNS queries as well, ... For external facing DNS servers ... > Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, forms, ...
      (Pen-Test)
    • DNS ACL ?
      ... I need a sanity check regarding DNS ACLs. ... For external facing DNS servers ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)