The UNIX and Linux Forums  
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.

Go Back   The UNIX and Linux Forums > Special Forums > Security
.
google unix.com



Security Discuss UNIX and Linux computer and network security, cybersecurity, cyberattacks, IT security, CISSP, OWASP and more.

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
DNS upgrade issues, bind9.5.0_P1 robsonde IP Networking 2 08-14-2008 08:23 PM
Gentoo: BIND Cache poisoning iBot Security Advisories (RSS) 0 07-11-2008 05:40 PM
TA08-190B: Multiple DNS implementations vulnerable to cache poisoning iBot Security Advisories (RSS) 0 07-08-2008 06:40 PM
Debian: New pdns-recursor packages fix cache poisoning vulnerability iBot Security Advisories (RSS) 0 04-10-2008 09:00 AM
how can we spoof ethernet by ARP cache poisoning on unix through a program ud4u IP Networking 1 02-11-2008 09:06 AM

Closed Thread
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish Bulgarian Greek Powered by Powered by Google
 
LinkBack Thread Tools Search this Thread Rating: Thread Rating: 1 votes, 5.00 average. Display Modes
  #1 (permalink)  
Old 08-13-2008
sparcguy sparcguy is offline Forum Advisor  
Registered User
  
 

Join Date: Nov 2006
Posts: 315
Dns cache poisoning upgrade to bind9.5.0p2

Hi again guys,

It seems this is a global thing affecting all the DNS bind versions prior to July 28 2008. I have my work cut out for me very soon, I see at least a handful of servers in my list that either need to patching or upgrading.

How many of you guys are affected? Anybody successfully upgraded for unix? Any problems encountered that we need to beware of?

US-CERT Vulnerability Note VU#800113
Internet Systems Consortium, Inc.
  #2 (permalink)  
Old 08-13-2008
amsct amsct is offline
Registered User
  
 

Join Date: Aug 2008
Location: Amsterdam, The Netherlands
Posts: 33
Depending on your current Bind versions, you might need to specify some configuration items explicitly inside the options block in named.conf:

- allow-query and allow-transfer
- check-names
- minimal-responses
- transfer-format
See Upgrading DNS Bind to 9.5.0 p2 | Unixplaza Blog
  #3 (permalink)  
Old 08-13-2008
sparcguy sparcguy is offline Forum Advisor  
Registered User
  
 

Join Date: Nov 2006
Posts: 315
thx for the info Amsct.

Tho I know the upgrade will only touch on the binary I just want to ask is there any requirement at all to lower the TTL prior to doing the upgrade?
  #4 (permalink)  
Old 08-14-2008
Neo's Avatar
Neo Neo is online now Forum Staff  
Administrator
  
 

Join Date: Sep 2000
Location: Asia Pacific
Posts: 6,711
Lowering the TTL is not necessarily a good thing for this issue.

See attached BlackHat presentation by Dan.
Attached Files
File Type: zip DMK_BO2K8.zip (1.51 MB, 16 views)
  #5 (permalink)  
Old 08-14-2008
sparcguy sparcguy is offline Forum Advisor  
Registered User
  
 

Join Date: Nov 2006
Posts: 315
I didn't know lowering TTL could be a problem.

WOW this is very interesting Neo
Closed Thread

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 06:03 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language Translations Powered by .
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0