[15502] in bugtraq
Re: NT DNS Server leaks administrator account name in SOA record
daemon@ATHENA.MIT.EDU (Mikael Olsson)
Tue Jun 27 18:41:06 2000
Mime-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 8bit
Message-Id: <3957C2BF.FCC19CD@enternet.se>
Date: Mon, 26 Jun 2000 22:53:19 +0200
Reply-To: Mikael Olsson <mikael.olsson@ENTERNET.SE>
From: Mikael Olsson <mikael.olsson@ENTERNET.SE>
X-To: Roy Hills <bugtraq-l@NTA-MONITOR.COM>
To: BUGTRAQ@SECURITYFOCUS.COM
Roy Hills wrote:
>
> [MS DNS leaking current NT "Administrator" user name]
>
> suggest that people who are concerned about this manually change
> their SOA record contact details to something
> generic like "postmaster@domain.com" until a fix becomes available.
I thought this might be worth mentioning, since there are a _lot_ of
people out there setting up their own systems that are unaware of
Internet best practices.
All domains should have a "postmaster" and "hostmaster" role
mailbox (or distribution list, alias, whatever).
The "correct" role mailbox to use given these two required mailboxes
would be "hostmaster". Not that it _really_ matters which one you use
as long as it's stated in the SOA record. But, as I said, you should
have a "hostmaster" mailbox regardless of which is listed in the SOA
record.
For more info on commonly used role mailboxes (including the
above), please see:
RFC 2142: "Mailbox names for common services, roles and functions"
http://www.imc.org/rfc2142
It's actually very informative reading and only a few pages long.
Highly recommended for pretty much everyone :-)
$.02
/Mike
--
Mikael Olsson, EnterNet Sweden AB, Box 393, SE-891 28 VRNSKVLDSVIK
Phone: +46-(0)660-29 92 00 Fax: +46-(0)660-122 50
Mobile: +46-(0)70-66 77 636
WWW: http://www.enternet.se E-mail: mikael.olsson@enternet.se