Linux Today: Linux News On Internet Time.
Search Linux Today
search.internet.com
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Become a Marketplace Partner

internet.commerce
Be a Commerce Partner














The Linux Channel at internet.com
Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Subscribe News
Subscribe PR
Subscribe Security

internet.com
IT
Developer
Internet News
Small Business
Personal Technology

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

 







Current Newswire:

Microsoft, other rivals slam Google Chrome OS

Intel Linux Graphics Shine With Fedora 12

Editor's Note: Do It Yourself "Cloud"

Google Chrome OS: First looks, first impressions

Kernel Log: Coming in 2.6.32 (Part 3) - Storage

TV Mythos Renewed: MythTV 0.22 with Many Improvements

Enhancing openSUSE 11.2: Adding Repositories and Packages

A Northwest Nobel option? (Linus for the Nobel Peace prize)

SECURITY: Cloud Computing Security Benefits, Risks and Recommendations

Keeping score in test-driven development with Python, PyLint, unittest, doctest,




Arcsight Engineer
The Computer Merchant, Ltd
US-DC-Washington

Justtechjobs.com Post A Job | Post A Resume
:Security Portal: DNS Security - closing the b(l)inds
Security Portal: DNS Security - closing the b(l)inds
Sep 29, 1999, 14 :08 UTC (1 Talkback[s]) (8049 reads)

(Other stories by Kurt Seifried)

"DNS is one of the basic services that makes the Internet work, without it there would be no "sun.com" or "microsoft.com" or "securityportal.com". At one point the entire list of computers on the Internet fit easily into a single file (usually /etc/hosts) which was (and still is) a simple table of names and IP addresses..."

"DNS provides a "phonebook" of hosts on your network, and like any company phone directory, it is an invaluable resource for someone planning an attack. Additionally, many companies now rely on services (such as email, or web based commerce) that rely on DNS servers to provide information to customers so that they can find the servers. However many DNS servers, and the information they provide, are woefully unprotected. Bind 8.x provides several facilities to control access to your DNS servers."

"The first step is to define ACL's (access control lists) in your named.conf file, and then to use the "allow-query" and "allow-transfer" directives to grant or revoke access to information that the DNS server provides. DNS servers typically provides two kinds of information, the most obvious being domains that they host, such as example.com. This service is usually critical, as without it internal machines can't find each other, and customers won't be able to find your web site, or email server. These domains usually contain a complete list of every piece of network attached equipment in your infrastructure (such as firewall-nt.example.com) that can give an attacker help when planning an assault on your network..."

Complete Story

Related Stories:
32BitsOnline: Book Review: "DNS and BIND" from O'Reilly (Sep 15, 1999)
SecurityPortal.com: Securing Domain Name Service (Jun 21, 1999)
BIND 8.2 released (Mar 16, 1999)
Network Computing: Developments in DNS: Investigating Bind 8 (Nov 28, 1998)


Index Mode   |   Flat Mode   |   Thread Mode   |   Thread Flat  
  Talkback(s) Name  and Date
Thank you Kurt.  DNS is one of the  ...   thanks   
Thomas Corriher
Sep 29, 1999, 16:50:19
 
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!






..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP

internet.commediabistro.comJusttechjobs.comGraphics.com

Search:

WebMediaBrands Corporate Info

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs