[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-security] Fwd: [EXPL] BIND 8.2.2-P5 DoS vulnerability(exploit, BIND_ZXFR)



"Jeff Lovell" <jlovell@xxxxxxxxxx> wrote
> As a measure to prevent attacks, you can add the following
> to the options section in your /etc/named.conf
> 
> allow-transfer { none; };
> 
> and run /etc/rc.d/init.d/named restart
> 
> Here is the modified default named.conf:
> 
> options { directory "/etc/named"; allow-transfer { none; }; };
> zone "." { type hint; file "db.cache"; };
> 
> See if that will stop it from crashing for now.  But you
> will not be able to do zone transfers.  If you still need
> to do zone transfers, put in the address/net to allow access.
> 
> 'man named.conf' for more details.
> 
> Jeff
> 

BINDv8.2.2 patchlevel 7 has been released on the ISC web/ftp site.  An 
announcement should be out soon.
Gerald