Security Incidents mailing list archives

Re: DNS server crashed


From: Jason Lewis <jlewis () jasonlewis net>
Date: Wed, 7 Feb 2001 07:51:09 -0500

I appreciate the suggestion, but it is difficult to change DNS servers on
production boxes.  I am the security guy, not the SysAdmin.  AS much as I
fight....  Politics plays a big role.  If it weren't for politics, all my
name servers would be upgraded.  It isn't a perfect world.

jas

-----Original Message-----
From: Incidents Mailing List [mailto:INCIDENTS () SECURITYFOCUS COM]On
Behalf Of Graphic Rezidew
Sent: Tuesday, February 06, 2001 11:24 PM
To: INCIDENTS () SECURITYFOCUS COM
Subject: Re: DNS server crashed


ever thought about djbdns? http://cr.yp.to
I'm pretty sure you could get it to compile.
It'll work fine if you just want something to
keep you from getting hacked until your new
boxen come in.



On Tue, Feb 06, 2001 at 06:47:21PM -0500, Jason Lewis wrote:
Anyone aware of exploits for the recent BIND security holes?  I had a name
server crash today.  Nothing in the logs that point to anything, it was
just
down.  It is the only box I can't upgrade BIND on.  It has a funky OS
install and I need to rebuild it from scratch.  I am waiting for new
boxes,
so it is low priority.

I suspect someone was attempting to hack it, but I can't find any
evidence.
It was just hung.

Thoughts?

jas
http://www.rivalpath.com

--
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
The word "spine" is, of course, an anagram of "penis".  This is true in
almost fifty percent of the languages of the Galaxy, and many people
have attempted to explain why.  Usually these explanations get bogged
down in silly puns about "standing erect".
                -- Douglas Adams, "The Hitchhiker's Guide to the Galaxy"
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Graphic Rezidew
rezidew () rezidew net


Current thread: