[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-security] DNS advise.



Hi,

 

Want to tell you all some good advise on how I got hacked by DNS (named) twice. In the GUI where you can type the IP that you want to be allowed to get zone transfers from the server (like the DNS2 server) you must never hit enter after the IP. If you do there will be two ";;" (think it was ";") instead of one at the end of the sentence generated in the script. This some how open up the DNS server for hacking. I never understood why I got this huge amount of zone transfers to IP`s I did not know, and as I could see in the log some IP still got denied zone transfers but other not. And it always ended up with my Raq`s getting hacked until I found out about this "bug".

When typing the IP and not "hit enter" after, I never see a zone transfer to IP I don’t have allowed.

This is youst a advise that have been working for me.

Kai R Schantz
euroweb as
Norway