Re: 99.9 % of Software/Hardware Firewalls DO-NOT.....

From: Lars M. Hansen (badnews@hansenonline.net)
Date: 01/04/02


From: Lars M. Hansen <badnews@hansenonline.net>
Date: Fri, 04 Jan 2002 12:26:26 GMT

On Thu, 03 Jan 2002 19:10:18 -0600, Spam Sucks spoketh

>
>Let me rephrase that. If I was to run a DNS server, and it was fully patched,
>are you aware of some vulnerability that would allow you to compromise it.
>
>I should have said patches are available to fix all known security holes to my
>knowledge. I did not mean to imply that people have applied these, because in
>general they don't.

If all known bugs have been patched, then there are no known
vulnerabilities. But there might be unknown ones.

What you want to do, is put your DNS server on the LAN and make it
unaccessible from the public internet. Then, only you can get to it...

Lars M. Hansen
http://www.hansenonline.net
(replace 'badnews' with 'lars' in e-mail address)



Relevant Pages

  • Re: 99.9 % of Software/Hardware Firewalls DO-NOT.....
    ... "Lars M. Hansen" wrote: ... If I was to run a DNS server, and it was fully patched, ... >>are you aware of some vulnerability that would allow you to compromise it. ... >>I should have said patches are available to fix all known security holes to my ...
    (comp.security.firewalls)
  • Re: Is MSIE dead as a browser - if Microsoft does not patch it then it is as far as I am concerned!
    ... M$ issuing patches "PDQ" is ... >> files served by the web server. ... this vulnerability ... the installed patch ...
    (microsoft.public.security.virus)
  • Re: Bad sectors... how bad?
    ... > Dude, linux is free, if MS want's to start giving away their OS's I'll ... >>> and the $100 upgrade is that the upgrade looks for previous installs. ... > online to fully update all the patches. ... >> So when a vulnerability is found you want to remain vulnerable for 6 ...
    (alt.comp.hardware.pc-homebuilt)
  • Re: Patch for CVE-2004-1334 ???
    ... default builds of Linux kernels with the Openwall patch applied since ... distros should be releasing their updates ... The vulnerability allows local users to gain root ... >> the kernel security patches ...
    (Linux-Kernel)
  • Re: Bad sectors... how bad?
    ... > complexity contains bugs and software written to fix bugs will contain ... >> and the $100 upgrade is that the upgrade looks for previous installs. ... online to fully update all the patches. ... > So when a vulnerability is found you want to remain vulnerable for 6 ...
    (alt.comp.hardware.pc-homebuilt)