[15502] in bugtraq

home help back first fref pref prev next nref lref last post

Re: NT DNS Server leaks administrator account name in SOA record

daemon@ATHENA.MIT.EDU (Mikael Olsson)
Tue Jun 27 18:41:06 2000

Mime-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 8bit
Message-Id:  <3957C2BF.FCC19CD@enternet.se>
Date:         Mon, 26 Jun 2000 22:53:19 +0200
Reply-To: Mikael Olsson <mikael.olsson@ENTERNET.SE>
From: Mikael Olsson <mikael.olsson@ENTERNET.SE>
X-To:         Roy Hills <bugtraq-l@NTA-MONITOR.COM>
To: BUGTRAQ@SECURITYFOCUS.COM

Roy Hills wrote:
>
> [MS DNS leaking current NT "Administrator" user name]
>
> suggest that people who are concerned about this manually change
> their SOA record contact details to something
> generic like "postmaster@domain.com" until a fix becomes available.

I thought this might be worth mentioning, since there are a _lot_ of
people out there setting up their own systems that are unaware of
Internet best practices.

All domains should have a "postmaster" and "hostmaster" role
mailbox (or distribution list, alias, whatever).

The "correct" role mailbox to use given these two required mailboxes
would be "hostmaster". Not that it _really_ matters which one you use
as long as it's stated in the SOA record. But, as I said, you should
have a "hostmaster" mailbox regardless of which is listed in the SOA
record.

For more info on commonly used role mailboxes (including the
above), please see:
RFC 2142: "Mailbox names for common services, roles and functions"
http://www.imc.org/rfc2142

It's actually very informative reading and only a few pages long.
Highly recommended for pretty much everyone :-)

$.02

/Mike

--
Mikael Olsson, EnterNet Sweden AB, Box 393, SE-891 28 VRNSKVLDSVIK
Phone: +46-(0)660-29 92 00         Fax: +46-(0)660-122 50
Mobile: +46-(0)70-66 77 636
WWW: http://www.enternet.se        E-mail: mikael.olsson@enternet.se

home help back first fref pref prev next nref lref last post