Firewall Wizards mailing list archives

RE: Does blocking TCP DNS packets keep your Bind safe?


From: "Adrian Brinton" <adrian () brinton to>
Date: Mon, 26 Mar 2001 21:21:38 -0800

I think you miss the point... I could go to any of my favorite '31337
warez' sites and download a nice easy to use exploit for BIND. Actually,
I would have a choice of many, for many versions. I can't say the same
is true for djbdns, regardless if one is better written, more secure, or
whatever.


Adrian Brinton


-----Original Message-----
From: Behm, Jeffrey L. [mailto:BehmJL () bvsg com]
Sent: Wednesday, March 21, 2001 11:18 AM
To: firewall-wizards () nfr com
Subject: RE: [fw-wiz] Does blocking TCP DNS packets keep your Bind safe?




since there are probably 100x more servers out there in the world 
running BIND, the likelihood of seeing or finding bugs on the 
platform, and the level of interest for people to design 
exploits are both going to be way higher than for a relatively
scarce product like djbdns.

security by obscurity. a valiant, but ineffective means of security.
_______________________________________________
firewall-wizards mailing list
firewall-wizards () nfr com
http://www.nfr.com/mailman/listinfo/firewall-wizards
_______________________________________________
firewall-wizards mailing list
firewall-wizards () nfr com
http://www.nfr.com/mailman/listinfo/firewall-wizards


Current thread: