Security Incidents mailing list archives

Re: DNS Scanning for blocking


From: Mathieu Mourez <matt () CPNICORE COM>
Date: Fri, 22 Dec 2000 10:07:40 -0500

Jonathan Rickman wrote:
No. While what they did may seem intrusive, it's no more illegal than
running nslookup against your domain name. Their reason for doing so is
perfectly legal as well. As the operator of an adult site, you can expect
this. Being added to a proxy's smut filter is the (HTTP) equivalent of
being added to the (SMTP) ORBS database. Not alot you can do about it.

BIND 8 supports the 'allow-transfer' directive to restrict which hosts can AXFR
your zone files. If you want to let other people to download your zone, you
may even just negate surfcontrol's IP block.

Merry (Christmas|Hanukkah) !

- Matt

+---------------------+---------------------+
| Mathieu Mourez      | W: 514-940-2891x132 |
| matt () cpnicore com   | C: 514-996-9626     |


Current thread: