Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Tony Earnshaw <tonni@billy.demon.nl>
To: Nick Drage <nickd@funkyjesus.org>
Cc: netfilter@lists.samba.org
Subject: Re: dns server
Date: 09 Jun 2002 09:40:41 +0200	[thread overview]
Message-ID: <1023608443.8429.56.camel@billy.demon.nl> (raw)
In-Reply-To: <20020608105857.I2090@funkyjesus.org>

[-- Attachment #1: Type: text/plain, Size: 1648 bytes --]

lør, 2002-06-08 kl. 11:58 skrev Nick Drage:

> > It depends what you want to do with it. And what DNS software you're
> > running. I.e., if it's BIND, you can do more with BIND 9 than you can
> > with BIND 8, more with BIND 8 than with BIND4.

> > Many security people might say that if you're running BIND 4 or 8, then
> > you shouldn't be. Some of them again might say that you should be
> > running BIND 9.2.

> I believe that the latest BIND 8.something is still OK, and version 8 is
> being maintained as far as security patches go.

Yes, but as I wrote: You can do more with BIND 9 than with BIND 8.

> As for the rest of the thread, you're best restricting that kind of access
> using named.conf as the problem is at layer 7 - the BIND application, not
> layer 3 - where netfilter mostly lives.

Again yes, but if you have a blanket DROP policy, you're going to have
to open up ports, aren't you? The question is, what ports and for which
protocols and using what policies and what tools that iptables places at
your disposition?

Have a look at hping2 (and most probably other tools and craftsmanship,
but hping2 is my favorite of all favorites) and see what nasty things
you can do with it, if you want to, and then have a look at what you can
drop with Netfilter, that BIND simply isn't capable of.

Best,

Tony
 
-- 

Tony Earnshaw

e-post:		tonni@billy.demon.nl
www:		http://www.billy.demon.nl
gpg public key:	http://www.billy.demon.nl/tonni.armor

Telefoon:	(+31) (0)172 530428
Mobiel:		(+31) (0)6 51153356

GPG Fingerprint = 3924 6BF8 A755 DE1A 4AD6 FA2B F7D7 6051 3BE7 B981
3BE7B981



[-- Attachment #2: Dette er en digitalt signert meldingsdel --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

  reply	other threads:[~2002-06-09  7:40 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-06-06 13:22 dns server Corin Langosch
2002-06-06 13:31 ` Francois Peyron
2002-06-06 13:37   ` Raymond Leach
2002-06-06 13:45     ` Maciej Soltysiak
2002-06-06 13:48       ` Raymond Leach
2002-06-06 14:00         ` Antony Stone
2002-06-06 14:36           ` Arne Sagnes
2002-06-06 15:06             ` Tony Earnshaw
2002-06-06 13:33 ` Antony Stone
2002-06-06 14:00   ` Daniel Bastos
2002-06-06 14:04 ` Tony Earnshaw
2002-06-08  9:58   ` Nick Drage
2002-06-09  7:40     ` Tony Earnshaw [this message]
  -- strict thread matches above, loose matches on Subject: below --
2002-06-08 10:21 Corin Langosch
2002-06-08 22:36 ` Nick Drage

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1023608443.8429.56.camel@billy.demon.nl \
    --to=tonni@billy.demon.nl \
    --cc=netfilter@lists.samba.org \
    --cc=nickd@funkyjesus.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox