Re: bind8, libpcap, tcpdump

Andrew Kohlsmith <[email protected]>
Newsgroups gmane.linux.lfs.security
Organization Linux From Scratch
Message-ID <[email protected]>
> It's worth noting that to anyone who follows the principle of least
> privlege to the letter when designing subsystems, their nameservers
> would only be vulnerable to attack from network blocks which their
> systems "trusted" enough to provide regular, recursive nameservice for.
> For any of you running a caching nameserver at home, this means that you
> should not have been vulnerable to this bug, provided your system was
> configured properly.

Absolutely.  It should also be mentioned that the bind8 exploits are _only_ 
for Bind 8.  Bind 9 has been out for quite some time now.  (A cursory check 
on my servers shows only one out of the lot still on BIND 8, but it's 
configured as you detail here so it's not a priority to upgrade.  :-)

Regards,
Andrew
-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.