In addition to upgrading to the newly patched versions of BIND, administrators should make sure their name servers restrict access to recursion.
Re: Users urged to patch serious hole in BIND 9 DNS server.
It's much easier to exploit this vulnerability on a name server that will process arbitrary recursive queries, since you can induce it to query a name server under your control or cause it to look up a domain name you want to spoof.
For more information on limiting access to recursion, may I suggest the two links at the bottom of our DNS Resources page, http://www.infoblox.com/library/dns_resources.cfm
|
Does Verizon's Voyager stack up to the iPhone? |
|
|
5 IT skills that won't boost your salary
[1,407]
Women 4 times more likely than men to cough up personal info
[589]
Japan's 10 funniest tech-related commercials [Videos]
[407]
Throwing away a promo CD is "unauthorized distribution"?
[1,265]
Adults too quick to dismiss educational video games
[682]
Attack of the iPhone clones [Slideshow]
[578]
10 things IT needs to know about AJAX
[1,258]
This Year's 25 Geekiest 25th Anniversaries [Slideshow]
[409]
|
|