[5043] in bugtraq

home help back first fref pref prev next nref lref last post

bind security: fear, uncertainty, and doubts

daemon@ATHENA.MIT.EDU (Paul A Vixie)
Tue Jul 29 14:26:32 1997

Date: 	Mon, 28 Jul 1997 21:56:09 -0700
Reply-To: Paul A Vixie <vixie@VIX.COM>
From: Paul A Vixie <vixie@VIX.COM>
To: BUGTRAQ@NETSPACE.ORG

if you don't enable updates for a zone, or you enable them only from hosts
within an intelligent (source routing prohibited, source addresses checked)
firewall, bind is immune to the "bind_nuke" attack published here recently.

updates aren't on by default, and according to rfc 2136 dns updates are not
recommended except from "localhost" which is assumed to be secure.  (though
i wish that more system vendors would disallow source-address 127.0.0.1 from
coming in off the network.)  for this reason we have not published a patch
to bind-8.1.1.  i expect that we will put bind-8.1.2 into beta testing in a
few weeks.  (note that we still won't have support for rfc 2137 or TSIG; if
any system vendors would like to fund that effort, we'd love to work on it.)

mountain.  molehill.

home help back first fref pref prev next nref lref last post