Re: TCP/IP Filtering

From: Herb Martin (news_at_LearnQuick.com)
Date: 08/25/03


Date: Sun, 24 Aug 2003 22:04:24 -0500


"TLW" <tlw@oceanlighthouse.com> wrote in message
news:OYwKUHmaDHA.3360@tk2msftngp13.phx.gbl...
> I have the same issue.
> Is there a way to solve this issue of the server responding to the DNS
> server from an arbitrary port so that "bad" UDP ports can be blocked?
> Possibly a product that will allow the server to use some ports as
> arbitrary?

Some clients can be told which address/port to use for
binding.

BIND can definitely do this -- Microsoft's RPC's can be locked
to certain ports with registry settings.

Not sure about MS DNS (vaguely think I may have read that but
this may be because I know I read this about BIND and have
seen the settings documented.)



Relevant Pages

  • [NEWS] BIND 9 DNS Cache Poisoning
    ... BIND 9 DNS Cache Poisoning ... source UDP port and DNS transaction ID can be effectively predicted. ... address of the target name server), and the destination UDP port (53 the ...
    (Securiteam)
  • [UNIX] Multiple Remote Vulnerabilities in BIND4 and BIND8
    ... ISS X-Force has discovered several serious vulnerabilities in the Berkeley ... Internet Name Domain Server (BIND). ... majority of DNS servers on the Internet. ... deployed recursive DNS servers on the Internet. ...
    (Securiteam)
  • Re: DNS Manipulation via IPTables or other means?
    ... You might use the BIND view functionality ... I thought I could alter DNS responses ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic ...
    (Security-Basics)
  • Re: DNS Manipulation via IPTables or other means?
    ... Not sure about iptables. ... I nwhat way is BIND not scalable -- ... I thought I could alter DNS responses ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ...
    (Security-Basics)
  • Re: your mail
    ... I even bought DNS and BIND from O'riley. ... For debugging Bind9, start by getting Bind to log a lot of stuff. ... continually on a busy production server. ...
    (freebsd-questions)