Re: named config



On 29 Jul at 17:31 Chris Davies <chris-usenet@xxxxxxxxxxxx> wrote in message
<q7t3m5x054.ln2@xxxxxxxxxxxxxxxxx>

Tony van der Hoff <news@xxxxxxxxxxxxxxxxxxxxx> wrote:
For any named gurus out there, I'm running BIND9 as a caching nameserver
under Debian etch.

As an important side issue to your actual question, please make sure that
you upgrade it ASAP. You may (or may not) have read about the DNS exploits
that are being talked about right now, but essentially it allows attackers
to poison one's DNS cache so that names map to the wrong IP addresses.
(Can you say bank website spoofing?)
[snip]

Aye:

bind9 (1:9.3.4-2etch3) stable-security; urgency=high

* Randomize UDP query source ports to improve forgery resilience.
(CVE-2008-1447)
-- LaMont Jones <lamont at debian dot org> Sun, 06 Jul 2008 19:19:53 -0600

Debian's pretty good with security patches, and I've got automatic
notification enabled. Thanks for the reminder!

--
Tony van der Hoff | mailto:news_0711@xxxxxxxxxxxxxx
Buckinghamshire, England
.



Relevant Pages

  • Re: named config
    ... Tony van der Hoff wrote: ... under Debian etch. ... that you upgrade it ASAP. ... attackers to poison one's DNS cache so that names map to the wrong IP ...
    (uk.comp.os.linux)
  • Re: Upgrade xorg in Sid breaks link
    ... today (I upgraded yesterday morning) so this is sure to generate ... I ran Debian Etch for some months, but about two weeks ago I decided to switch to Sid. ... This morning I realized I had negected to install a little app I use from time to time, so I tried to install it and aptitude complained about a missing package. ... may as well do an upgrade. ...
    (Debian-User)
  • Re: Upgrade xorg in Sid breaks link
    ... today (I upgraded yesterday morning) so this is sure to generate ... I ran Debian Etch for some months, but about two weeks ago I decided to ... This morning I realized I had negected to install a ... may as well do an upgrade. ...
    (Debian-User)
  • lost sources.list file during atempted upgrade
    ... I'm a newbie to Debian Etch but not new to Linux in general. ... I was reading the Debian Reference doc section 5.2 going to upgrade from i believe the terms are Etch Stable to testing. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx with a subject of "unsubscribe". ...
    (Debian-User)