Vulnerability Development mailing list archives

RE: Bind recursive queries quota.


From: Robert Buckley <rbuckley () synapsemail com>
Date: Mon, 22 Jul 2002 06:45:35 -0400


Thomas Cannon Wrote:
* Yes. Turn off recursive queries going to your external DNS servers. They
should only resolve domains that they serve, and junk anything else that
comes to them.
*

Most conciencous people will, but there are many sites that permit recursive
queries. 
Recursive queries have to be allowed internally too, so the threat is still
present.





-----Original Message-----
From: Thomas Cannon [mailto:tcannon () noops org]
Sent: Friday, July 19, 2002 11:50 PM
To: Guanglong Zhang
Cc: Robert Buckley; 'vuln-dev () securityfocus com'
Subject: Re: Bind recursive queries quota.



Current thread: