Re: bind8, libpcap, tcpdump

Dagmar d'Surreal <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
On Tue, 2002-11-19 at 15:35, Steve Wolfe wrote:
> > It's worth noting that to anyone who follows the principle of least
> > privlege to the letter when designing subsystems,
> 
>  (snip)
> 
> > ...at the top of the named.conf, add an ACL (access control list) like:
> 
> (snip)
> 
> > ...and in the options section of the named.conf, we add:
> 
> (snip)
> 
> > At the top of our named.conf, we'd be adding a new ACL like this...
> 
> (snip)
> 
> > ...we'd be using an ACL to globally disable zone transfers, and then
> > we'd have a zone entry that looked a bit like this...
> 
>     Geez.  Imagine a car dealer telling you "No, it won't blow up on you,
> as long as you take these five basic steps to customize the engine...."

Your analogy is woefully incorrect.  From where I sit, it's more like
telling people their car will last longer if they avoid driving it into
solid objects or bodies of water.  Just because someone _can_ toss
together a five line named.conf does not mean that's the intelligent
thing to do.

-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.