Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Securing DNS Server

From: Bennett Todd <bet(at)rahul.net>
Date: Tue Nov 05 2002 - 15:41:49 EST

2002-11-05-14:36:41 Naman Latif:
> Try adding this to named.conf:

It may make it easier to firewall, but it's got other consequences.

It may, depending on the implementation in the server, limit the server to one outstanding query at a time, which would only be acceptable for exceptionally low-volume servers (home servers, perhaps). Or it may cause all concurrent queries to share the same src port, rather than being issued distinct src ports, which would have the consequence that it would be much, much easier to forge a reply packet and send it to the server to poison its cache.

Either way, the consequence may, perhaps, be worse than just allowing incoming UDP to a wide range of ports on the DNS server.

It really comes down to a question of whether you can harden that server adequately.

-Bennett

Do you need help?X

  • application/pgp-signature attachment: stored
Received on Wed Nov 6 16:59:59 2002

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:03:20 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library