Re: 99.9 % of Software/Hardware Firewalls DO-NOT.....

From: Lars M. Hansen (badnews@hansenonline.net)
Date: 01/01/02


From: Lars M. Hansen <badnews@hansenonline.net>
Date: Tue, 01 Jan 2002 02:19:41 GMT

On Mon, 31 Dec 2001 19:21:10 -0600, Patrick Farrell spoketh

>Ric Griffy wrote:
>>
>> I, for one do not have any internal dns servers. The reason? It is an easy
>> security hole. Our DMZ uses only our ISP's dns servers. Our firewalls will
>> only allow OUTGOING to those specific dns servers.
>> Yes, the dangers of dns have been obvious to me for a long time. Until a
>> better method is developed, I will continue to let this be handled by our
>> ISP.
>> Thank you,
>> Ric Griffy
>
>Would you care to illustrate what you perceive to be the dangers?

Linux/Un*x DNS servers have had numerous exploits giving hackers ways to
gain root access to these servers...

Lars M. Hansen
http://www.hansenonline.net
(replace 'badnews' with 'lars' in e-mail address)



Relevant Pages

  • Re: 99.9 % of Software/Hardware Firewalls DO-NOT.....
    ... Ric Griffy wrote: ... Our DMZ uses only our ISP's dns servers. ... the dangers of dns have been obvious to me for a long time. ...
    (comp.security.firewalls)
  • Re: 99.9 % of Software/Hardware Firewalls DO-NOT.....
    ... for one do not have any internal dns servers. ... security hole. ... Our DMZ uses only our ISP's dns servers. ... the dangers of dns have been obvious to me for a long time. ...
    (comp.security.firewalls)
  • Re: 99.9 % of Software/Hardware Firewalls DO-NOT.....
    ... So how is it that anyone is able to run any dns servers. ... boxes that I'm not. ... the dangers of dns have been obvious to me for a long time. ... >>> Ric Griffy ...
    (comp.security.firewalls)
  • Re: Forwarding or Stub Zones?
    ... My DMZ has approx 30 servers providing various services. ... internet. ... The servers on the DMZ do not query our ISP they query the DNS servers on ...
    (microsoft.public.win2000.dns)
  • Re: DNS Best Practices
    ... > Windows NT enviroment but will soon be embarking on Active Directory 2003. ... > this DMZ and all are isolated from the internal network. ... Forward from your internal AD DNS servers to ... (or straight to the Internet Root servers). ...
    (microsoft.public.windows.server.general)