Re: Help DNS cache poisoning

From: Lanwench [MVP - Exchange] (lanwench_at_heybuddy.donotsendme.unsolicitedmail.atyahoo.com)
Date: 09/30/04


Date: Wed, 29 Sep 2004 22:09:07 -0400

anonymous@discussions.microsoft.com wrote:
>> -----Original Message-----
>> Tony wrote:
>>> We are running a WIN2K server with DNS that was exploited
>>> with DNS cache poisoning. It was trying to redirect our
>>> email to another server. We found what appeared to be a
>>> fix in the MS knowledgebase article 241352.
>> <snip
>>>
>>> When we checked this on the server there was no value in
>>> the registry, but when going through the gui the Secure
>>> cache against pollution box was checked.
>>> Should there also be a registry setting when this check
>>> box is enabled?
>>> Any ideas how this server could get exploited with this
>>> setting enabled?
>>
>> What inbound ports are open in your firewall?
>>>
>>> ANy assistance would be greatly appreciated.
>>
>> open ports are 25 (SMTP) and 23 (Telnet). This server resides on the
>> DMZ. .

Are you using forwarders, or relying on root hints?



Relevant Pages

  • Re: Help DNS cache poisoning
    ... In the future, you need to post to multiple groups, it's best to crosspost ... >> Are you using forwarders, or relying on root hints? ...
    (microsoft.public.security.virus)
  • Re: Cant resolve .orgs
    ... but I have always used forwarders. ... is recommended practice. ... >> Set up forwarders to your ISP's DNS servers instead of relying only ... >> on root hints. ...
    (microsoft.public.win2000.dns)
  • Re: Cant resolve .orgs
    ... L> Set up forwarders to your ISP's DNS servers instead of relying ... L> only on root hints. ...
    (microsoft.public.win2000.dns)
  • Re: Help DNS cache poisoning
    ... resides on the ... >Are you using forwarders, or relying on root hints? ...
    (microsoft.public.security.virus)
  • Re: Windows 2008 DNS forwarders and root hints
    ... IsSlave from 0 to 1 and back again. ... Similar setting with 2003, but 2008 does everyone a favor by graying it out if no forwarder is present, which forces it to use the forwarders and the IsSlave disappears. ... When you TICK "Use root hints if no ... I spent a good 30 minutes messing with this, and each time I was able to successfully resolve queries. ...
    (microsoft.public.windows.server.dns)