Re: About DNS (BIND) with Database

From: Bill Vermillion (bv_at_wjv.com)
Date: 11/18/03

  • Next message: Crist J. Clark: "Re: IPSec VPN & NATD (problem with alias_address vs redirect_addr ess)"
    Date: Tue, 18 Nov 2003 10:01:22 -0500
    To: freebsd-isp@freebsd.org
    
    

    On Tue, Nov 18, 2003 at 12:35 , Simon Gray exclaimed "Las Cucarachas
    entran, Pero no puede en salir", and then rambled on saying with:
     
    > > >personally i wouldn't use bind, its had a bad security history.

    > > YEP, and it is VERY OLD HISTORY, but it goes back 3 years.
    > > So what's your gripe about security vulnerabilities in BIND
    > > since early 2001? If you don't have any concrete, recent
    > > examples, then stop the FUD. There are reasons some people
    > > don't want to use BIND, but security isn't one of them.

    > My apologies if this thread has hit a nerve, I wasn't picking
    > at anyone. I'm just giving my point of view.

    > The history may be old in terms of computing, but I won't how
    > many vulnerable systems are still out there? System admins that
    > may not even know how to upgrade or even know that the vulns
    > exist.

    > bind advisories:
    > http://www.cert.org/advisories/CA-2002-19.html
    > http://www.cert.org/advisories/CA-2001-02.html
    > http://www.cert.org/advisories/CA-1999-14.html

    > Plus http://www.isc.org/products/BIND/bind-security.html isn't
    > a very good track record is it?

    Not as bad as other utilities out there. Since this is an ISP list
    I would think that all here keep things up to date.

    The worst problem in BIND is not in the above list and it was
    sometime before the last one there. In Linux systems the
    vulnerability gave the cracker root access. In FreeBSD systems
    DIND just stopped running

    > Track records are pretty much all you have to go on with
    > software, unless you audit all the code yourself.

    And monitor the security lists is pretty much a requirement for
    anyone at an ISP. Vulnerabilites occur everywhere.

    > If people want to use bind or any other package, they do so at
    > Itheir choice. 'm just saying in my opinion I think there are
    > Ibetter alternative.

    > If you're happy using bind, use bind. If you're happy with
    > windows 95, use it.

    Happy with Win95. I got fed up with the restriction and very poor
    performance of DOS 2.0 - which looked good on paper - that after
    6 months I parted out my IBM and moved to Unix and have never
    looked back. I do have MS systems to use when I need to - probably
    2 or 3 times a week for short periods - but 99% its' on a *n*x
    system. I learned early :-)

    Bill

    -- 
    Bill Vermillion - bv @ wjv . com
    _______________________________________________
    freebsd-isp@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-isp
    To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"
    

  • Next message: Crist J. Clark: "Re: IPSec VPN & NATD (problem with alias_address vs redirect_addr ess)"

    Relevant Pages

    • RE: [Full-disclosure] RE:DONT SEND ME AGAIN PLS
      ... XSS vulnerabilities in Google.com ... XSS vulnerabilities in Google.com (GroundZero Security) ... It lists the folks that they might ...
      (Full-Disclosure)
    • [Full-Disclosure] Fw: BIND 9.2.2 Vulnerabilities?
      ... Subject: BIND 9.2.2 Vulnerabilities? ... | The ISC website lists the following as of today: ... | "ISC has discovered or has been notified of several bugs which can result ...
      (Full-Disclosure)
    • BIND 9.2.2 Vulnerabilities?
      ... The ISC website lists the following as of today: ... "ISC has discovered or has been notified of several bugs which can result ... Upgrading to BIND version 9.2.2 is strongly recommended. ... discussion about any specific vulnerabilities. ...
      (Bugtraq)
    • Re: [fw-wiz] An article from Peter Tippett/TruSecure...
      ... >> The point that Peter's making is that chasing vulnerabilities just ... SANS doesn't. ... It lists 25 known issues for W1 alone. ... Yep - this is what it all boils down to: Sales Pitch Alert: Security Comes ...
      (Firewall-Wizards)
    • [Full-Disclosure] Disclosure Debate FW: [ISN] When to Shed Light
      ... Information security, in particular, cannot exist. ... full disclosure results in FEWER hands at work in this process, ... Microsoft because of how dependent publishers are on access to beta software ... > I think actively seeking vulnerabilities is just plain destructive. ...
      (Full-Disclosure)