l i n u x - u s e r s - g r o u p - o f - d a v i s
L U G O D
 
Next Meeting:
September 2: Social gathering
Next Installfest:
TBD
Latest News:
Aug. 18: Discounts to "Velocity" in NY; come to tonight's "Photography" talk
Page last updated:
2009 Jul 31 14:45

The following is an archive of a post made to our 'vox-tech mailing list' by one of its subscribers.

Report this post as spam:

(Enter your email address)
[vox-tech] [fwd] BIND 9 denial of service exploit
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[vox-tech] [fwd] BIND 9 denial of service exploit



Fwd of a fwd of a fwd:

-bill!

----- Forwarded message from Graham Freeman -----

Date: Thu, 30 Jul 2009 17:57:45 -0700
From: Graham Freeman
Subject: [Cernio Colo] Fwd: [bitfolk] BIND 9 denial of service exploit

Hey, folks,

Good info from Andy Smith re protecting against BIND9 exploits.

-G


Begin forwarded message:

> From: Andy Smith
> Date: 30 July, 2009 03:22:48 PDT (CA)
> Subject: Re: [bitfolk] BIND 9 denial of service exploit
>
> Hello,
>
> On Thu, Jul 30, 2009 at 12:09:31AM +0100, Jan Henkins wrote:
>> Andy Smith wrote:
>>> If you're running BIND 9 you'll want to upgrade because of:
>>>
>>> https://www.isc.org/node/474
>>>
>>
>> Thanks! Those running Lenny and the latest Ubuntu should be OK,  
>> although
>> it seems Etch is running behind (no updated debs available tonight,
>> could be tomorrow). RedHat/CentOS/Fedora people, here is what looks  
>> to
>> be a useful link (could not test it, not running any of these in
>> production):
>>
>> *http://tinyurl.com/6y4rb9*
>
> For those who are unable to upgrade, you can firewall off dynamic
> update packets like so:
>
> iptables -A INPUT -p udp --dport 53 -j DROP -m u32 --u32  
> '30>>27&0xF=5'
>
> Cheers,
> Andy
>
> -- 
> http://bitfolk.com/ -- No-nonsense VPS hosting
>
> "I am the permanent milk monitor of all hobbies!" -- Simon Quinlank

----- End forwarded message -----

-- 
-bill!
Sent from my computer
_______________________________________________
vox-tech mailing list
vox-tech@lists.lugod.org
http://lists.lugod.org/mailman/listinfo/vox-tech



LinkedIn
LUGOD Group on LinkedIn
Sign up for LUGOD event announcements
Your email address:
facebook
LUGOD Group on Facebook
'Like' LUGOD on Facebook:

Hosting provided by:
Sunset Systems
Sunset Systems offers preconfigured Linux systems, remote system administration and custom software development.

LUGOD: Linux Users' Group of Davis
PO Box 2082, Davis, CA 95617
Contact Us

LUGOD is a 501(c)7 non-profit organization
based in Davis, California
and serving the Sacramento area.
"Linux" is a trademark of Linus Torvalds.

Sponsored in part by:
O'Reilly and Associates
For numerous book donations.