Bind 4 and 8 Vulnerabilities
eecue writes "The world's most popular DNS package is once again vulnerable. Even the advisory says it's only a matter of time before worms are written.... just like a couple years ago. I guess this is why i run tinydns."
How hard is it to write a program that tells people that 'www.slashdot.org' = 66.35.250.150 using UDP port 53???
Idiots...
Frankly, anyone still using BIND 4 deserves to get rooted.
Anyone still running BIND 8 should be given a good slap and told to upgrade.
Anyone running BIND 9, well done.
That page does not contain the words "subnet" "view" "horizon" or "internal". So that page hardly shows me how. I've just always found the TinyDNS zone format and configuration to be much harder to use than BIND 9.
MORTAR COMBAT!
If you think TinyDNS is any good. HAHAHAHAHAHAHA. HAHAHAHAHA. Oh man. HAHAHAHA. Michael you are such a tool. And you have to moderate this down. And you have to think. "I am superior, I know better than this AC, I am better."
But you are wrong.
DJB is a strange person. With a horrible license (must install in gay non standard directory that not ONE *nix dist uses, EVER) . Horribly feature deprived software and he LIES about awarding cash to those who exploit his software. Qmail is such a piece of trash. I could listen to an argument advocating postfix, but TinyDNS?
Roll your own or working with BIND. You didn't even read the advisory. I didn't see any exploit code, and ISC already patched the theoretical exploit.
So here we have a responsible vendor, a good, massive scalable solution to which we all owe a billion successful queries served, and you sit there and smarmily say "I use some strange non standard DNS server with like 10 other people and we are cool."
Who is to say beyond a doubt that if hundreds of millions of people used DJB's crap it wouldn't be a cornucopia of trash? Why don't people use stack guard CC? Why not chroot jail EVERYTHING?
Because it's mental masturbation. Good software is software that is fixed responsibly and quickly. Bad software has this Titanic unsinkable "design" to it. And when the kiddies root something like that its heaven - because no one uses it enough to notice or people think its infallible.
Michael, this is just another editorialization that serves as a testament to your wanna-be jobless sexless fat moronic self is a blithering moronic fool.
Go back to some broken distribution of Linux with Beta C libraries and broken Red Hat compilers. I would like not to have my FreeBSD be polluted further with this piece of garbage of a thread.
Michael, you also can't afford SCSI hard drives. And I laugh at that. Linux on IDE want a cheesy Mac zealot. You can't afford a crapintosh either.
I didn't think that:
emerge djbdns
was all that hard! But I guess you don't run Gentoo
Derek