Re: 53 udp/tcp

From: David (davidwnh@adelphia.net)
Date: 11/28/02


From: "David" <davidwnh@adelphia.net>
Date: Thu, 28 Nov 2002 16:02:37 GMT

Since anything is possible I guess it comes down to weighing the risks.
Compare the vulnerabilities of running your own additional service with
those present by doing things the way you are doing them.

> >
> > I've once even read about an obscure way to tunnel IP traffic by
> > encoding it into hostnames and doing a DNS request on those names (for
> > example: 872782362474454272454648246429.foo.com), which would rely on
> > having somebody on the outside with control over the DNS server that
> > controls foo.com. The server would receive the request and decode the
> > data which is embeded into the weird hostname.
> >
> > I've never seen anybody actually USE this method, though :-)
> >
> > --
> > Juergen Nieveler
> > Support the ban of Dihydrogen Monoxide: http://www.dhmo.org/
> > "The people united can never be ignited!"-Sgt. Colon,Ankh-Morpork Watch
> > http://bofh.gmxhome.de / juergen.nieveler@web.de / PGP Supported!
>
>



Relevant Pages

  • Re: Query ACL
    ... > query" statement available since bind 8... ... However there's a netmask feature ... ... the DNS Server service uses local subnet priority. ... Manage the discretionary access control list on DNS servers running ...
    (microsoft.public.win2000.dns)
  • Re: OT : Good XP Domain Admin book?
    ... >> unrelated to real world hostnames, like 'localdomain'. ... > Then that subdomain can be managed by the AD DNS server, ... > how active directory does domain and catalog lookups. ...
    (uk.rec.motorcycles)
  • DNS Error 4011 on Active Directory-Integrated DNS
    ... Integrated DNS, and I've recently been getting the following error ... Active Directory is functioning properly and add or update this domain ... DOMAIN\Administrators -- Full Control ... The DNS server seems to function properly, but I'd like to fix this ...
    (microsoft.public.windows.server.dns)
  • Re: DNS setup
    ... Alan Curtis wrote: ... The "rndc" is for remote control (however it can ... Put a DNS server on *one* machine, and that DNS server is used by all ...
    (freebsd-questions)
  • Re: Another BIND vulnerability (cache poisoning)
    ... be made to their own DNS server and they check if each DNS request was ... it deems the DNS server to be vulnerable. ... I'm not sure why being "not connected to the internet" helps in this ... Note that the MS patch for this breaks zonealarm. ...
    (comp.os.vms)