[aklug] Re: Munkeys can setup a bind DNS server

From: Larry Collier <larry@medease.com>
Date: Wed Mar 26 2008 - 15:09:44 AKDT

My knowledge of DNS is limited to I request a name and I get the IP address
and all is well. I'm sure Many of us reading this are in the same boat, more
or less.

Could one of you more knowledgeable gurus give a quick -- no huge tome --
explanation of what probably occurred?

Larry

On Wednesday 26 March 2008 14:58:06 Arthur Corliss wrote:
> On Wed, 26 Mar 2008, dhull wrote:
> > I don't know what GCI is doing for DNS. I'm guessing their doing
> > something extra. Either that or they have know idea how to setup DNS.
> >
> > 1. Install Linux
> > 2. Install BIND9
> > 3. Done!
> >
> > That's all it takes. By default BIND is a cashing name server. With a
> > setup that's that simple there's no excuse for broken DNS.
>
> You're speaking out of your depth, Damien. A monkey can set up a DNS
> server that's still vulnerable to DNS cache poisoning and acting as an open
> recursive DNS server.
>
> A properly trained monkey, however, will set up their DNS with ACLs so that
> only their net blocks can use them for resolving queries. I'm willing to
> bet that if I examined your configuration I could point out lots of
> problems with your setup.
>
> Don't start slinging aspersions until you know for certain your monkey is
> house broken. And knows how to use a spell checker.
>
> --Arthur Corliss
> Live Free or Die
> ---------
> To unsubscribe, send email to <aklug-request@aklug.org>
> with 'unsubscribe' in the message body.

---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.
Received on Wed Mar 26 15:09:53 2008

This archive was generated by hypermail 2.1.8 : Wed Mar 26 2008 - 15:09:53 AKDT