Slashdot Mirror


New DoS Vulnerability In All Versions of BIND 9

Icemaann writes "ISC is reporting that a new, remotely exploitable vulnerability has been found in all versions of BIND 9. A specially crafted dynamic update packet will make BIND die with an assertion error. There is an exploit in the wild and there are no access control workarounds. Red Hat claims that the exploit does not affect BIND servers that do not allow dynamic updates, but the ISC post refutes that. This is a high-priority vulnerability and DNS operators will want to upgrade BIND to the latest patch level."

197 comments

  1. Interesting by PhunkySchtuff · · Score: 2, Interesting

    This is very interesting. I'm sure the people behind BIND will scramble to get things sorted out ASAP, but I wonder how long it will take other vendors (Apple, I'm looking at you!) to release a patch.

    I do have to wonder about exploits like this that seem initially incredibly serious, yet nothing much comes from them and they don't seem to get exploited to the extent that you might expect they would - this one reminds me of l0pht's famous claim that they can bring down the internet in 30 minutes. If this vulnerability is really as serious as they say, and as easy to exploit as it appears to be then in the wrong hands, this could really be an "internet killer"

    1. Re:Interesting by d3matt · · Score: 2, Informative

      so... any BIND server would be down for a bit... anyone with a caching name server would still be able to surf.

      --
      I am d3matt
    2. Re:Interesting by houstonbofh · · Score: 2, Interesting

      Only to sites already cached. The more unusual sites would just be all gone. What do you bet http://downforeveryoneorjustme.com/ is not cached by your DNS server right now?

    3. Re:Interesting by Minwee · · Score: 5, Funny

      It is now.

      This vulnerability also gives the three people running DJB DNS a much needed opportunity for some smugness.

    4. Re:Interesting by kriebz · · Score: 5, Funny

      I was under the impression they had smugness to spare.

    5. Re:Interesting by HARRRRRR · · Score: 1

      *bzzzzt* sorry pal...

      you're assuming nobody follows rfc1912.

      also, what happens when the (ridiculously configured) host you're trying to browse goes to do a reverse lookup on your address?

    6. Re:Interesting by rs79 · · Score: 1

      " This is very interesting. I'm sure the people behind BIND will scramble to get things sorted out ASAP, but I wonder how long it will take other vendors (Apple, I'm looking at you!) to release a patch. "

      I'd be less concerned about that than I would be about how long it will take for people to do something about this on their nameservers. IMO the best update to BIND is DJBDNS but that's just me.

      Either way, there are FIVE HUNDRED THOUSAND nameservers out there. Some of them still run Bind 4.7.

      --
      Need Mercedes parts ?
    7. Re:Interesting by MrMr · · Score: 1

      Now it is.

    8. Re:Interesting by QuantumRiff · · Score: 1

      Only when they run DJB DNS on their macbooks...

      --

      What are we going to do tonight Brain?
  2. Use Unbound or NSD by nwmcsween · · Score: 5, Informative

    I don't want to bash BIND but it has had a fair amount of sec issues (well a lot), try unbound or nsd instead http://unbound.nlnetlabs.nl/ http://www.nlnetlabs.nl/projects/nsd/

    1. Re:Use Unbound or NSD by medlefsen · · Score: 5, Informative

      or djbdns. We use it where I work and other than a slight adjustment to djb-land it has been wonderful. I know people appreciate how powerful BIND is and maybe some people need that. I suspect though that most people just need their DNS servers to serve their DNS records or provide a caching DNS server for local lookups and for that BIND seems to be bloated and insecure.

    2. Re:Use Unbound or NSD by buchner.johannes · · Score: 1

      for dns caching, dnsmasq is nice too, but I'm not certain that it has a good security history.

      --
      NB: The message above might reflect my opinion right now, but not necessarily tomorrow or next year.
    3. Re:Use Unbound or NSD by abigor · · Score: 2, Interesting

      PowerDns for the win. Plus it reads legacy BIND zone files.

    4. Re:Use Unbound or NSD by TheLink · · Score: 1

      I'm certain dnsmasq does not have good security history.

      Google for: dnsmasq vulnerability

      --
  3. Well.. by TechyImmigrant · · Score: 2, Funny

    Well DNS operators do appear to be in a bit of a bind don't they?

    --
    Evil people are out to get you.
    1. Re:Well.. by Anonymous Coward · · Score: 0

      They would agree, but keep making errors in their assertions.

    2. Re:Well.. by num42 · · Score: 1

      I was BOUND but then i became UNBOUND by PowerDNS. ;-)

      --
      "morning is a state of mind ;)"
  4. Ain't what it used to be.... by mcrbids · · Score: 3, Interesting

    Was once the day whe a notice like this would kick off a flurry of migrationn plans, compiler scripting, compiling, and restarting servers in the dead of night. (and bonuses to match!)

    But now?

    # yum -y update && shutdown - r now

    Sometimes I pine for the 'good old days'. A little. (ok, hardly at all)

    --
    I have no problem with your religion until you decide it's reason to deprive others of the truth.
    1. Re:Ain't what it used to be.... by MichaelSmith · · Score: 1

      You seem to be just taking all changes and rebooting. I do that all the time on my ubuntu laptops but I wouldn't manage my servers that way.

      Having said that patching in netbsd will require a compilation at my end. It would be nice if I could just update a package. The infrastructure is right there for it...

    2. Re:Ain't what it used to be.... by ScytheBlade1 · · Score: 4, Informative

      I'm just hoping that CentOS pushes out the update before 10:00 PM MST today.

      Why?

      So I'll get my daily e-mail status update, telling me to do just that: run yum, and then restart (just bind) -- as opposed to seeing it tomorrow.

      As a footnote, it is generally a good thing to subscribe to whichever vendor's security-announce list that you use. It is really nice getting e-mail notifications of security-related package updates. CentOS has one, right here: http://lists.centos.org/mailman/listinfo/centos-announce

    3. Re:Ain't what it used to be.... by lordkuri · · Score: 4, Insightful

      Why in the holy hell would you reboot a server to put a new install of BIND into service?

    4. Re:Ain't what it used to be.... by palegray.net · · Score: 4, Insightful

      Because modern-day admins don't know how to restart a service?

      Oh, wait, these are fellow Linux "admins" we're talking about...

    5. Re:Ain't what it used to be.... by DeathElk · · Score: 1

      And hope to hell you've got some sort of LOM for when your server doesn't come back up.

    6. Re:Ain't what it used to be.... by Anonymous Coward · · Score: 0

      On Debian, apt-get restarts services that it updates. I would expect yum to do the same.

    7. Re:Ain't what it used to be.... by QuoteMstr · · Score: 1

      The strange thing is that he used shutdown -r now instead of this newfangled reboot the kids like to type. If you know what shutdown does, you should know when to not use it.

    8. Re:Ain't what it used to be.... by Anonymous Coward · · Score: 0

      Must be a Windows user.

    9. Re:Ain't what it used to be.... by Olmy's+Jart · · Score: 1

      This isn't Windows...

      # yum -y update named\* && service named restart

      (Not sure if yum [or apt] would restart named and NOT willing to take the chance.)

    10. Re:Ain't what it used to be.... by houstonbofh · · Score: 2, Funny

      Remember when "shutdown -rfn" would work? Ahh... The days of youth.

    11. Re:Ain't what it used to be.... by Antique+Geekmeister · · Score: 2, Insightful

      Because you may have a stack of other pending updates, particularly kernels, and this has been the first "gotta switch" update in quite some time for those core servers? Also because without the occasional reboot under scheduled maintenance, it's hard to be sure your machines will come up in a disaster. (I've had some gross screwups in init scripts and kernels cause that.)

    12. Re:Ain't what it used to be.... by c0y · · Score: 1

      Because the OP probably had a lingering kernel update anyway. They come out with enough regularity that, despite having been current on my boxes sometime in the last two weeks, I found another one after returning from vacation this weekend. It wasn't critical and not worth taking the time for immediate action on. Still, I'm not that brave. I like to examine yum a little more closely.

    13. Re:Ain't what it used to be.... by Anonymous Coward · · Score: 0

      init 6

    14. Re:Ain't what it used to be.... by secolactico · · Score: 3, Informative

      You seem to be just taking all changes and rebooting. I do that all the time on my ubuntu laptops but I wouldn't manage my servers that way.

      More so because some package managers (such as CentOS) tend to replace customized init.d files with the stock ones (renaming the ones you had). This is not really a big deal, but it sometimes breaks some services.

      --
      No sig
    15. Re:Ain't what it used to be.... by Elshar · · Score: 1

      I see that there's several versions of BIND in the pkgsrc binary packages tree, wouldn't a new patched one show up there fairly quickly? That would solve you having to recompile anything. Not that BIND generally takes a long time to compile on fairly modern hardware..

    16. Re:Ain't what it used to be.... by MichaelSmith · · Score: 1

      You are right but I would have to find a clean way to uninstall the built in one. Otherwise I might pick up part of the wrong version. I think the debian approach of putting much or all of the base system inside built in packages makes upgrades a lot easier.

    17. Re:Ain't what it used to be.... by FishWithAHammer · · Score: 3, Funny

      I never heard that one, but please tell me it stands for "Right Fucking Now."

      --
      "You can either have software quality or you can have pointer arithmetic, but you cannot have both at the same time."
    18. Re:Ain't what it used to be.... by mcrbids · · Score: 1

      Because modern-day admins don't know how to restart a service?

      Oooh! Oooh! I think I can get this one! Either of these should work:

      # service named restart;
      # /etc/rc.d/init.d/named restart;

      But... if you have a properly designed network, why the **** wouldn't you reboot your name server? Given that there are minimally TWO of them registered for your domain name, that the DNS protocol is designed to seamlessly fail over in the event of a failure, rebooting the name server will have no discernible effect for any end user, but will provide assurance that all libraries and settings have taken full effect, as the O/S vendor intended.

      I have 4 name servers, and move them around as needed to ensure low-latency, redundant connections. Fault tolerance is most important. Any server or network can go down and still result in my ability to change DNS and publish globally on short notice in the event of a severe outage. A single nameserver being down for the ~ 1-2 minutes it takes to reboot is a non-issue.

      Downtime: 0

      Peace Of Mind: 1

      You tell me, (ahem) ninja super-admin-who-knows-how-to-(re)start-a-service?

      --
      I have no problem with your religion until you decide it's reason to deprive others of the truth.
    19. Re:Ain't what it used to be.... by palegray.net · · Score: 1

      Sure, you should have four authoritative nameservers. There is still no excuse for bouncing an entire box when a simple service restart is completely sufficient. Do you honestly issue a host restart every time you want [insert DNS daemon here] to kick over? If you do, you're completely retarded.

      Assuming you have failover for other services running on your network (as you probably should if you're working in an organization that gives two rips about service availability), do you restart entire servers each time you want to bounce Apache?

      Have a cold beer and think about this for awhile. Please refrain from touching any keyboards until you've figured it out.

    20. Re:Ain't what it used to be.... by palegray.net · · Score: 2, Funny

      I think I'm going to alias "reboot" to 'echo "go read some man pages and come back later"' on a bunch of servers now :)

    21. Re:Ain't what it used to be.... by Anonymous Coward · · Score: 0

      No need to take a chance. You have logs, and if you can't find anything conclusive from them (shouldn't be hard, but sometimes you don't know what to look for) you could restart the service manually without rebooting.
       

      That doesn't mean it's not a good idea to reboot -- I'm on the fence on the issue. What if, for instance, the fix was in libc and it affected multiple running processes? You could figure out all those processes and restart each so they link in the new version of the library, or in many cases it's more practical to just reboot.
       

      Depending what your server's use and criticality are different approaches will be more practical.

    22. Re:Ain't what it used to be.... by FireFury03 · · Score: 2, Insightful

      More so because some package managers (such as CentOS) tend to replace customized init.d files with the stock ones (renaming the ones you had). This is not really a big deal, but it sometimes breaks some services.

      If you are modifying packaged files that aren't marked as %config in the RPM spec then you're doing it wrong. 99% of the time you don't need to modify those files anyway, the other 1% of the time you really should be building a custom package and adding it to yum's exclude list.

    23. Re:Ain't what it used to be.... by FireFury03 · · Score: 1

      Because modern-day admins don't know how to restart a service?

      Oooh! Oooh! I think I can get this one! Either of these should work:

      # service named restart;
      # /etc/rc.d/init.d/named restart;

      Properly designed packages do "service foo condrestart" on upgrade anyway, so most of the time you don't need to manually restart anything.

      But... if you have a properly designed network, why the **** wouldn't you reboot your name server? Given that there are minimally TWO of them registered for your domain name, that the DNS protocol is designed to seamlessly fail over in the event of a failure, rebooting the name server will have no discernible effect for any end user,

      I'm afraid you're wrong. If one of your DNS servers disappears, stuff will continue to work *slowly*. If you have 2 NS records then each server will get 50% of the requests. That means that 50% will go to the dead server and have to wait for a timeout before trying the working one.

      There are other reasons for not rebooting - restarting bind takes approximately 2 seconds, rebooting one of my servers takes several minutes. As with all reboots I then have to spend time checking that all the other services on the box came back up ok (yes, they should, but these things don't always work so you have to check).

      but will provide assurance that all libraries and settings have taken full effect, as the O/S vendor intended.

      There is only one OS vendor I can think of who intends you to reboot after anything gets updated, and they don't do Linux distributions...

    24. Re:Ain't what it used to be.... by Anonymous Coward · · Score: 1, Informative

      Still works, according to shutdown(8) on CentOS.

      -r : reboot
      -f : skip fsck
      -n : don't go through init, just kill everything

      Would be a pretty fast way of rebooting, especially if you have lots of slot K* scripts in /etc/init.d/*

      It's not recommended, though, because you never know how much "just kill everything" is going to destroy... Corrupt files, etc.

    25. Re:Ain't what it used to be.... by ChristofferC · · Score: 1

      telinit 6

    26. Re:Ain't what it used to be.... by Anonymous Coward · · Score: 0

      newfangled? from reboot(8) on FreeBSD:

      HISTORY
                A reboot utility appeared in Version 6 AT&T UNIX.

    27. Re:Ain't what it used to be.... by Anonymous Coward · · Score: 0

      Yeah, they use this funky 'service' command instead of the one true way: hand-running the script in /etc/init.d

    28. Re:Ain't what it used to be.... by Anonymous Coward · · Score: 0

      Why do modern day admins update services using vendor repositories ?

      Compile your own like we did in the old days.

    29. Re:Ain't what it used to be.... by FishWithAHammer · · Score: 1

      That's not as funny.

      Color me disappointed.

      --
      "You can either have software quality or you can have pointer arithmetic, but you cannot have both at the same time."
    30. Re:Ain't what it used to be.... by skarphace · · Score: 1

      Yeah, they use this funky 'service' command instead of the one true way: hand-running the script in /etc/init.d

      Running a daemon as a service keeps it monitored. If the service failed for any reason, it's restarted. Totally hands-off for the admin.

      (That is, if it has the same behavior as svscan as I recall...)

      --
      Bullish Machine Tzar
    31. Re:Ain't what it used to be.... by houstonbofh · · Score: 1

      You have to have been involved when it occurred. There is a reason -f is skip fsck, not just fsck. We knew what it meant, but we had to have something to put in the manual.

    32. Re:Ain't what it used to be.... by FishWithAHammer · · Score: 1

      Before my time; I had a XENIX machine in the early 90's, but I was five years old when I got it and switched to DOS/Windows not long after. Only got back into Linux around 2000 or so.

      Care to elaborate? :-)

      --
      "You can either have software quality or you can have pointer arithmetic, but you cannot have both at the same time."
    33. Re:Ain't what it used to be.... by houstonbofh · · Score: 1

      You have to go back to the old Sun OS and BSD stuff of the 80s. http://en.wikipedia.org/wiki/SunOS The old Sun workstations (and sun workstations http://en.wikipedia.org/wiki/SUN_workstation ) were very popular at universities. Unix then was kind of a closed and open source. It was commercial, but everyone who bought the hardware had the source code. So patches commonly went beck in if they were good. When virtual memory started extending shutdown times, some shorter commands were needed. Especially when there was an environmental reason to shutdown and save your work NOW. I am not sure, but I think "shutdown -rfn" was actually in common use before fsck was.

      Funny, now that I look back... Early VMS and Unix was a community a lot like modern open source. Probably because it started with a lot of the same people, and GNU was cheaper.

  5. All versions of Bind 9? by Yvan256 · · Score: 2, Funny

    Good thing I'm using FreeDOS!

    1. Re:All versions of Bind 9? by tygerstripes · · Score: 5, Funny

      But it's a DOS vulnerability!!! Sheesh, read the title...

      --
      Meta will eat itself
    2. Re:All versions of Bind 9? by Anonymous Coward · · Score: 0

      He probably think that on /. we read the articles and not the titles...

  6. At least someone agrees that BIND 9 had issues... by bogaboga · · Score: 2, Interesting

    According to this document, BIND 9 has issues including being monolithic, having a "Bad Process Model", Hard to Administer and Hard to Hack. That's not a good reputation to have.

    To some extent, these issues apply to everything Linux save for the last point. I am waiting for the time these points will not apply to Linux and its associated software.

    I must say that understanding BIND's configuration file was not that easy for me at first but after trying several times, I can say I am almost an expert. Things can be made simpler though. A text based interactive system could be of a lot of help. Tools like Webmin come in handy too though they require that a system be running initially.

  7. Only effective against MASTERS... by Olmy's+Jart · · Score: 5, Informative

    From the advisory: "Receipt of a specially-crafted dynamic update message to a zone for which the server is the master may cause BIND 9 servers to exit. Testing indicates that the attack packet has to be formulated against a zone for which that machine is a master. Launching the attack against slave zones does not trigger the assert."...

    So an obvious workaround is to only expose your slave DNS servers and to not expose your master server to the Internet. That's part of "best common practices" isn't it? You have one master and multiple slaves and you protect that master. Come on, this is pretty simple stuff. Just simple secure DNS practices should mitigate this. Yeah, if you haven't done it that way to begin with, you've got a mess on your hands converting and it's easier to patch. But patch AND fix your configuration.

    1. Re:Only effective against MASTERS... by jurv!s · · Score: 1

      agreed. ++

      --
      sigs are for fools and trolls. no signature is *always* appropriate. you should turn them off in your preferences.
    2. Re:Only effective against MASTERS... by Jurily · · Score: 1

      That's part of "best common practices" isn't it?

      Two posts up there is someone mentioning a reboot to solve this. Best practices seem like rocket science around here...

    3. Re:Only effective against MASTERS... by totally+bogus+dude · · Score: 1

      Hmm, both of my public servers are 'masters' because the zones are synced via rsync over SSH from an internal server which actually has the master copy of the zones. However as far as bind is concerned, they public-facing ones are masters.

      I could potentially trick it into thinking it's a slave zone but seems too fiddly/risky, so I'll just wait for it to be patched. Nagios will tell me if they stop working, anyway.

    4. Re:Only effective against MASTERS... by Olmy's+Jart · · Score: 1

      Perhaps you should rethink that mistake and create a real "master" and make them "slaves". The system was designed this way for a reason. It baffles me why people do things this this way.

    5. Re:Only effective against MASTERS... by raddan · · Score: 4, Insightful

      Because lots of people don't want intruders being able to affect the actual zone data in case an outward-facing DNS server gets compromised. Using SSH to transfer zone data is much easier and more secure than BIND's own zone transfer mechanisms (e.g., you can automate and schedule them), and you don't have to worry about zone transfers through firewalls. Troubleshooting all the weird crap that can happen between different DNS daemons all supposedly doing regular AXFRs is a real pain in the ass. SSH makes life easier.

      If having a DNS machine on the Internet that thinks it is a master really is a mistake, when then, BIND9 is a piece of shit. This is the most straightforward thing a DNS daemon should be asked to do.

      Nowhere in BIND's manual does it say people have to use BIND in a master/slave setup.

    6. Re:Only effective against MASTERS... by totally+bogus+dude · · Score: 1

      I do it that way mostly because I didn't previously consider "type master" to be a potential vulnerability (they don't have dynamic DNS or anything fancy enabled). Maybe it is time I looked into djbdns, now that it's no longer a pain in the ass to install.

      As for not using the built-in zone transfer method, that's partly because I don't particularly like it, but mostly because I don't see any reason to allow access to our internal hosts from our DMZ unless absolutely necessary -- and this is not a case where it's "absolutely necessary". My own sync mechanism ensures that all transfers are initiated from the internal host rather than from an untrusted public facing server, and the content DNS servers are always up to date.

      Having a play now, it seems pretty feasible to configure it as a slave but not use bind's zone transfer mechanism, using 127.0.0.1 as the master. The only issue is almost all my domains were immediately considered expired since the zones are only updated when they're actually changed. I can sort of work around that by setting the expires time really high, but it appears to now be used as the time to cache NXDOMAIN results which could have some unpleasant side effects. It seems touching the zone file solves that... so maybe I can schedule a job to touch them and reload bind each day?

      I guess it's doable, but it seems like a lot of hoops just to avoid the software's built-in stupidity. Maybe it really is time to switch to something else. Thanks for the advice.

    7. Re:Only effective against MASTERS... by psyclone · · Score: 1

      Copying zone files over ssh means you then have to rndc reload/reconfig every time you change a single A record.

      With a "normal" hidden master + slaves setup, at least you can send Notifies which will cause the slaves to query the master and update the zone without a reload. Also, this is the only sane way to provide secondary DNS for a trusted third party.

      If you have a lot of zones, it can take a while to reload bind. If you only have a handful of zones, and you don't do secondary DNS, I'm sure reloading is quick.

    8. Re:Only effective against MASTERS... by kju · · Score: 1

      There is no need to reload all zones. You can easily detect which zonefiles have changed since the last reload and do "rndc reload ".

    9. Re:Only effective against MASTERS... by totally+bogus+dude · · Score: 2, Informative

      As kju responded, you can reload on particular zones if you want. The logs seem to suggest that bind itself only actually reloads the zones which have changed (i.e. mtime is newer than the last time it was loaded). I only get messages that it's loading every zone if I actually restart bind (stop and start), telling it to reload I only get messages about zones that have actually been changed.

      I haven't noticed any performance hit from doing a simple reload, but I only have 120 zones.

      If we were supplying secondary DNS for an (un?)trusted third party then yes I'd use bind's zone transfer mechanism. But we don't so it's not an issue - we only serve DNS for things we host/manage ourselves.

    10. Re:Only effective against MASTERS... by Fastolfe · · Score: 2, Informative

      So I'm responding not because I disagree with your conclusions, but I disagree with the logic you're using to justify them:

      Because lots of people don't want intruders being able to affect the actual zone data in case an outward-facing DNS server gets compromised. ...
      If having a DNS machine on the Internet that thinks it is a master really is a mistake, when then, BIND9 is a piece of shit. This is the most straightforward thing a DNS daemon should be asked to do.

      You start off with a reasonable statement (that you don't generally want compromised DNS servers to allow for the modification of data), but then you say bind9 is a piece of shit because it's a best practice that the masters (which hold the data) shouldn't be exposed to the public. Which is it?

      Using SSH to transfer zone data is much easier and more secure than BIND's own zone transfer mechanisms

      Would you care to elaborate on that? Doesn't TSIG secure zone transfers? TSIG is just as easy to set up as SSH keys are.

      (e.g., you can automate and schedule them)

      How much more automated can you make automatic zone transfers? What better scheduling of zone transfers than when the zones are modified?

      you don't have to worry about zone transfers through firewalls

      The only thing you need to open through the firewall is TCP and UDP port 53. Most firewalls make this easy, because "Serve DNS through the firewall" is a common configuration for firewalls.

      Troubleshooting all the weird crap that can happen between different DNS daemons all supposedly doing regular AXFRs is a real pain in the ass. SSH makes life easier.

      SSH makes life easier for someone that understands SSH, and does not understand DNS or firewalls.

      That being said, there are valid reasons you might not prefer to run a DNS master as the source for your slaves/shadow masters, and SSH might even be a good way to push your zone files out to those machines, but you have not provided any of those reasons.

    11. Re:Only effective against MASTERS... by Fastolfe · · Score: 1

      DNS queries are not encrypted, so if you believe the contents of your DNS zones should be secret, you'd better hope nobody queries them. You may be interested in TSIG, which can authenticate your secondaries to your master. If you'd prefer to store and manage your zone files "offline", pushing them out to one or more masters through SSH or something might be the right thing to do, but if you already have an internal master, and need to update some public-facing slaves/shadow masters, there's no reason to re-invent DNS zone transfers.

    12. Re:Only effective against MASTERS... by totally+bogus+dude · · Score: 1

      Well the SSH is only used a convenient transport mechanism, with a nice side effect of some kind of authentication that the host it thinks its transferring the data to really is that host. But all the transfers happen through our internal network anyway, so it's not really important. The reason it's preferred is because the internal server connects to the DMZ server, rather than the other way around. We try to avoid letting DMZ hosts contact internal servers whenever possible, under the assumption that the DMZ server will one day be controlled by someone we don't like. That's why it's in a different network segment, after all.

      The internal master server doesn't actually run bind, though there's no particular reason it couldn't. The master puts together the zone files using an in-house templating system, then copies the internal versions to our internal resolvers (which also handle recursive requests for web browsing and so on), and copies the public versions to the public servers whenever I tell it to.

      As per the article, with this vulnerability access controls don't help. So if an attacker compromised our public servers, they'd be able to use this to shut down the internal server (since the slaves need to be able to contact the master). Not so bad since this is just a DoS, but what if it could be used to execute code? Now the internal server is trivially compromised using the same flaw that was used to compromise your public server.

      And what's the benefit? So we can avoid using "type master" in a config, which apparently doesn't just mean "don't try to update the zone from another server, your copy is fine and always accurate" but also means "and also do retarded things like process dynamic DNS update packets even if it's not enabled"?

      Fair enough, no software is perfect and we always have to do stupid workarounds for stupid features -- it's part of the job. But I still reserve the right to bitch about it. And I think I will switch to different, less "featureful" software. Though with the aforementioned templating system we're moderately invested in the bind zonefile format so will need to use something compatible with that.

    13. Re:Only effective against MASTERS... by coolgeek · · Score: 1

      This might help too.

      --

      cat /dev/null >sig
    14. Re:Only effective against MASTERS... by Anonymous Coward · · Score: 0

      You start off with a reasonable statement (that you don't generally want compromised DNS servers to allow for the modification of data), but then you say bind9 is a piece of shit because it's a best practice that the masters (which hold the data) shouldn't be exposed to the public. Which is it?

      In a "stealth primary" setup, all of your DNS daemons are going to think they're "masters". My point was that any DNS daemon that can't securely serve zone data on the Internet is a POS. My criticism is not limited to BIND in this regard.

      Clearly, there are differences between "slave" and "master" in BIND's logic, but from a practical perspective, what's the difference? If an organization thought they were "smart" because all of their outward facing DNS machines are "slaves", but an attacker can compromise those machines, what's the practical difference? Their DNS records are still going to get served up compromised. Whether those machines think they are "slaves" or "masters" is beside the point.

      Doesn't TSIG secure zone transfers? TSIG is just as easy to set up as SSH keys are.

      Arguments about TSIG key length aside, TSIG doesn't offer us anything that SSH doesn't. SSH + rsync is working fine for us, and it allows us to run our outward-facing DNS machines "naively". Our SSH+rsync/rndc script even lets us send named.conf files, which we do regularly, and it allows us to maintain and control our zone data centrally.

      How much more automated can you make automatic zone transfers? What better scheduling of zone transfers than when the zones are modified?

      It's about control for us. We run split-horizon DNS across various parts of our organization. In some cases, there are 4 views for the same zone data, depending on where you are. It is often the case that we want to update the zone data on the master and start serving it to a particular view, but wait to push out updates for other views. Since our SSH+rsync/rndc scripts are neatly packaged into shell scripts for each update location (like this colo, or that colo), I can do this very easily with our setup. Maybe BIND has some native way to do this, but our setup is working fine with what we've got, so I moved on.

      The only thing you need to open through the firewall is TCP and UDP port 53. Most firewalls make this easy, because "Serve DNS through the firewall" is a common configuration for firewalls.

      OK, you're right-- this wasn't really a problem with AXFR traffic itself. It was a problem with a third party at a colo who didn't understand the difference between source port and destination port. He was essentially refusing connections from his DNS server because they had the wrong source port (because his DNS machine the initiator of the transfer, and was thus not talking on port 53). That same kind of boneheaded mistake could happen with SSH, too. The difficulty in troubleshooting it came down to the fact that the guy was using a firewall appliance, a DNS appliance, and didn't know how to look at packet dumps.

      SSH makes life easier for someone that understands SSH, and does not understand DNS or firewalls.

      I think a choice quote from Dan Bernstein is appropriate here. For the record, we run BIND, not djbdns, but I listen to his advice, because he is often right:

      There has been some work on improving the zone-transfer protocol: a NOTIFY mechanism that wakes up the slaves (after a delay, and without a failure notice when something goes wrong); an experimental IXFR mechanism for incremental zone transfers (although the BIND implementation doesn't work for zone files modified by hand or by external tools); and several proposed security mechanisms, notably TSIG. BIND's May 2001 IXFR and TSIG implementations are supposedly free of the bugs that caused crashes, data corruption, and root exploits in previous versions of BIND. The BIND compa

    15. Re:Only effective against MASTERS... by Fastolfe · · Score: 1

      Clearly, there are differences between "slave" and "master" in BIND's logic, but from a practical perspective, what's the difference?

      You're absolutely right: a compromised server can't be trusted to give faithful replies, regardless of how bind has it configured. I think the recommendation to not run your primaries exposed is intended to protect the zone data itself, not the queries served by the machine (though, in theory, that's what DNSSEC is for). Many DNS configurations involve a single machine that acts as a DNS master, and on that machine are the only copies of the "live" zone files. If that machine gets compromised, it requires a fair bit of manual effort to recover the zone files from backups, replay any updates that needed to be made, and return to service.

      In more complex setups (such as yours), the live zone files are not stored exclusively on the masters. They come from Somewhere Else (a config repository, LDAP, whatever), and you need some sort of out-of-band process to get the data to the DNS masters to be served. SSH/rsync/whatever are perfectly fine ways to do that OOB transfer. But for most setups, the simplistic configuration makes the most sense, especially if you have to deal with dynamic updates, where it may be difficult to propagate changes back to your config repository.

      TSIG doesn't offer us anything that SSH doesn't.

      Which is essentially what I was trying to say: TSIG and SSH solve the same authentication problem, so if your source is a DNS server, and your destination is a DNS server, why reinvent zone transfers?

      The next time I mention something about the way I run my network, I'll make sure my explanation is up to your standards. Sheesh.

      Run your network however you prefer! Just don't advocate for your design, and rail against more common configurations and their associated best practices, using reasons that do not support your arguments. You have valid reasons to run your systems the way that you do, so use them to justify your design, but be aware that they do not extend to cover other configurations.

    16. Re:Only effective against MASTERS... by Fastolfe · · Score: 1

      We try to avoid letting DMZ hosts contact internal servers whenever possible ... The master puts together the zone files using an in-house templating system

      Both of these are great reasons to populate your masters with your zone data out-of-band.

      And what's the benefit?

      Dynamic updates become difficult if your masters get their data OOB, since they have no way of knowing how to propagate those updates back to the source. It just depends on your needs and your setup. For the majority (?) of configurations, having an inaccessible master doing zone transfers to exposed secondaries is perfectly reasonable. For more complex setups such as yours, it's not, but that design has its own set of costs.

    17. Re:Only effective against MASTERS... by psyclone · · Score: 1

      Reloading a zone is fine when you've changed an existing zone. I do this via: rndc reload ${zone} on the hidden master which sends notifies to the slaves.

      However, you must do a reconfig for bind to see new zones.

    18. Re:Only effective against MASTERS... by psyclone · · Score: 1

      Reloading a zone is fine when you've changed an existing zone.

      However, you must do a reconfig for bind to see new zones. (e.g. a list of zones is included from named.conf) Unfortunately, doing a full reconfig on > 120,000 zones takes awhile. (A few minutes at least)

      But yeah, on a simple setup like yours, stick with ssh. You don't have to setup rndc keys, and you keep your configs much simpler, hence bind is more secure. And a reconfig happens in seconds with only a few hundred zones.

  8. Upgrade the damn thing! by mongrol · · Score: 0, Flamebait

    Honestly, why do they insist on running such an important backbone infrastructure piece on a no longer support Microsoft operating system is beyond me.

  9. For goodness sake upgrade.... by syousef · · Score: 4, Funny

    ...to Windows! DOS is just so 80's and 90's it's not funny.

    (Suggested mod: +1 funny)

    --
    These posts express my own personal views, not those of my employer
    1. Re:For goodness sake upgrade.... by Anonymous+CowHardon · · Score: 0

      Si, creo que tres o cuatro seria mucho mas moderno.

    2. Re:For goodness sake upgrade.... by syousef · · Score: 1

      Si, creo que tres o cuatro seria mucho mas moderno.

      I' m apesadumbrado, no hablo español (solamente me utilice Babelfish)

      --
      These posts express my own personal views, not those of my employer
    3. Re:For goodness sake upgrade.... by Sicarul · · Score: 2, Funny

      hahaha automatically translated Spanish is so funny (Spanish is my mother language) Though, i don't know what he meant, he said "Yes, i think three or four would be much more modern"... i don't see how it applies to it's previous post... three or four windows? O.o

    4. Re:For goodness sake upgrade.... by Anonymous+CowHardon · · Score: 0

      I was referring to DOS. If you don't get it, ask your mother.

    5. Re:For goodness sake upgrade.... by Anonymous Coward · · Score: 0

      Modded: -1 you-suggested-a-mod

    6. Re:For goodness sake upgrade.... by Anonymous Coward · · Score: 0

      "Yes, i think three or four would be much more modern"... i don't see how it applies to it's previous post... three or four windows? O.o

      DOS , tres , cuatro ...

  10. Re:At least someone agrees that BIND 9 had issues. by Anonymous Coward · · Score: 1

    Difficult compared to what? DJBDNS is much more difficult to wrangle. It's really not that bad if you attempt to learn it.

  11. djb by dickens · · Score: 4, Funny

    Somewhere I think djb is managing to both smile and raise his eyebrows simultaneously.

    1. Re:djb by siddesu · · Score: 1

      came for the djb mention, leaving satisfied.

      / yes, I am.

    2. Re:djb by rs79 · · Score: 1

      Praise be to Dan and may peace be upon him.

      --
      Need Mercedes parts ?
    3. Re:djb by DNS-and-BIND · · Score: 0, Flamebait
      Uh, actually, having an acquantance with the man: he is probably slobbering, shouting obscenities at rival Open Source teams, having hurtful paranoid fantasies about how the NTPD team is out to get him, and considering how hateful his next rant against people who oppose him should be.

      Maybe this is inaccurate - let's ask the New York Times for a more nuanced profile.

      --
      Shutting down free speech with violence isn't fighting fascism. It IS fascism!
    4. Re:djb by Anonymous Coward · · Score: 1, Informative

      None of that changes the fact that his software is several orders of magnitude more secure than the competition.

      Him being an asshole doesn't change any of that and the constant harping on about it smacks of resentment and an inferiority complex.

    5. Re:djb by Anonymous Coward · · Score: 0

      Daily dose.

    6. Re:djb by __aaxwdb6741 · · Score: 1

      I considered using djbdns until I stumbled across his inflammatory and borderline-fanatic attitude against BIND. What the hell, man? It's just a DNS server. Get over it.

    7. Re:djb by dickens · · Score: 1

      I use his software even though I do know that he has some strong opinions, and probably some ridiculously strong opinions. He's not a politician, it's clear.

      The stuff is beautifully simple. Qmail too.

  12. LDAP based Zone updates by Zombie+Ryushu · · Score: 1

    This is a reason why I want to be able to do LDAP based zone updates.

    1. Re:LDAP based Zone updates by Olmy's+Jart · · Score: 1

      How would that help with this? You don't even need dynamic updates enabled for this to be exploited.

  13. Servers behind Firewalls by Bilbo · · Score: 2, Insightful

    It's unlikely that, if you're running a DNS server inside of your private network, someone on the outside is going to be able to hit it. But then, like all other vulnerabilities, you combine this one with a couple of other attacks (such as a non-privileged login), and all of the sudden you've got something really dangerous. :-(

    --
    Your Servant, B. Baggins
    1. Re:Servers behind Firewalls by Olmy's+Jart · · Score: 2, Insightful

      A server behind a firewall does not imply a server on a private network. You can have firewalls in front of a DMZ on a public address providing services. Firewalls are used for much more than merely "private networks". Those are two orthogonal issues.

      OTOH... A master on a private network providing zone feeds to slaves on various other networks (firewalled or not) on public addresses would be a very good idea.

    2. Re:Servers behind Firewalls by Anonymous Coward · · Score: 0

      Uh, and for some reason you're not concerned about attacks from the private network? I hope you don't actually administer systems for a living.

    3. Re:Servers behind Firewalls by Antique+Geekmeister · · Score: 1

      Please remember that most "private" networks aren't. They have laptop or VPN access to potentially compromised hosts, which may insert attacks from behind your typical firewalls. I've had considerable difficulty explaining this to management who have, effectively, been lied to for years by their own staff who refuse to accept responsibility for the existing insecure mess, and who are uninterested in the unglamorous and unpopular work of fixing it.

    4. Re:Servers behind Firewalls by Bilbo · · Score: 1

      Good point, especially since it is claimed that even servers which are not configured to accept dynamic updates are still vulnerable.

      --
      Your Servant, B. Baggins
  14. Re:At least someone agrees that BIND 9 had issues. by profplump · · Score: 5, Informative

    Recent versions of BIND (8+) are not terrible to administer, and have much more reasonable data files. Older version were *really* nasty, and had a data file format so complicated that we invented a dedicated zone-transfer mechanism just so people could send DNS data to each other.

    And while djbdns uses an unconventional admin system with lots of environmental variables, that's a one-time setup (that is probably done in large part by your package manager) and the actual data files are dead-simple -- plain text, one record per line, can do DNS lookups at build time, can concatenate files, etc. There are valid complaints to be made about djbdns, but I don't think "difficult to wrangle" is one of them.

  15. No need to restart bind after updating using yum by dusanv · · Score: 2, Informative

    It gets restarted automatically. Check system.log.

  16. Okay, I read the ISC alert. by mmell · · Score: 1, Troll
    They're right. This is a major exploit, especially in view of the fundamental nature of name services to the internet. With repeated application (or by combining with DDoS techniques) I could see holding an entire domain down for an extended period of time. Now, then . . .

    Only a fool would configure public-facing DNS servers as masters, although I've seen it done. Only the king of the land of fools would put his domain's real DNS master on a public-facing network. Thus, only domains administered by fools should be directly affected. Darwin for teh win!

    1. Re:Okay, I read the ISC alert. by Tetch · · Score: 1

      > Only a fool would configure public-facing DNS servers as masters

      While I must agree with your basic assertion here [if not BIND's :-)], something that is often disregarded by non-security folks is that security threats can arise from within the organisation ...

      It only takes one malicious employee to bring in an attack tool from outside - I haven't seen any exploit PoC code for this, but such a tool might consist of 100 lines of C and a C compiler.

      --
      If you don't pray in my school, I won't think in your church.
    2. Re:Okay, I read the ISC alert. by mmell · · Score: 1

      It's the same old story - the only truly secure system is disconnected from tne network, powered down and disassembled - and even then, I wouldn't bet my life on it to be absolutely secure!

    3. Re:Okay, I read the ISC alert. by Akatosh · · Score: 1

      Only a fool would configure public-facing DNS servers as masters

      At a minimum you're going to be 'type master' for localhosts forward and reverse and broadcast zones as per rfc1912. You're also going to be master for rfc1918 space if it's a recursive name server. The word 'master' in the context of this bug is the bind configuration option 'type master', present in ?all? bind configurations, not the name server that controls updates to others.

    4. Re:Okay, I read the ISC alert. by Anonymous Coward · · Score: 0

      NO! Not recursive! Bad Administrator!

      Recursive DNS servers are for internal networks. DNS servers which face the internet should be Authoritative for their domain. Not recursive. You want a DNS lookup on my domain, fine. You want a DNS lookup on www.somesite.com - use your own internal DNS server, or the one you get from your ISP. The only thing my public-facing DNS servers should be able to answer is queries about mydomain.com (and, yes, I have one).

    5. Re:Okay, I read the ISC alert. by Akatosh · · Score: 1

      Yes and no. Riddle me this: are your isp's recursive name servers public facing? The internal network in this case is a public network, and a malicious virus infested one at that.

  17. Pray it comes back by russlar · · Score: 1

    # yum -y update && shutdown -r now

    and pray to FSM that it comes back up.

    --
    Anybody want my mod points?
  18. suggested mod -1 historical by Anonymous Coward · · Score: 0

    +1 hysterical

  19. No alerts from normal channels? by Anonymous Coward · · Score: 0

    I have not received any alerts from the normal channels via email, such as US Cert, SANS, etc.. but i clearly see they have the alert posted. 8 hours in and IBM/ISS does not have a block signature we can deploy.
    I noticed the brief post to NANOG and began my research and deployed.
    The update to the ports tree hit shortly after the ISC update so there must be some chatter out there.

    We have updated our DNS servers, do you think we can expect another upgrade with a better fix like the last round of updates?

    FYI: we have not seen an attempt to be exploited, i expect this to have changed by morning.

  20. Always do a reboot test ... by ZeekWatson · · Score: 4, Insightful

    If you're running a serious server you should always do a reboot test after installing any software. I've been burned many times by someone doing a "harmless" installation only to find out 6 months later a critical library was upgraded with an incompatible one (a recent example is expat 2.0) and the server doesn't boot like it should.

    Always reboot! Even with the super slow bios you get in servers nowadays it should only take 2 minutes to be back up and running.

    1. Re:Always do a reboot test ... by DNS-and-BIND · · Score: 1

      So...with linux, you should always reboot upon applying any sort of application update. I weep for the future of our computing race.

      --
      Shutting down free speech with violence isn't fighting fascism. It IS fascism!
    2. Re:Always do a reboot test ... by Vancorps · · Score: 2, Interesting

      Why? You're DNS servers are clustered and load balanced right? rrright? Those of us that need our infrastructure up don't think twice about rebooting even during the day! A golden age we live in indeed when I can just take the server out of the load balancer rotation, apply updates, perform reboot rest, and then put it back into rotation repeating the steps for all servers in the cluster.

    3. Re:Always do a reboot test ... by Anonymous Coward · · Score: 0

      I sometimes do it to check and make sure everything will start on a reboot.

    4. Re:Always do a reboot test ... by MrMr · · Score: 1

      I wouldn't consider a simple parser that replaces a critical library a 'harmless' installation.
      Please tell which repository managed to mess up that badly, so I can steer away from it in the future.

    5. Re:Always do a reboot test ... by sago007 · · Score: 2, Insightful

      If you're running a serious server you should always do a reboot test after installing any software.

      You should obviously wait to outside working hours in case it actually breaks something.

      If you apply an update over ssh you should test that you can create a new ssh connection before you disconnect the first one.

    6. Re:Always do a reboot test ... by dbIII · · Score: 1

      It's what nights, weekends or redundant systems are for. It's not as if you make major changes every week to things that might muck up the startup sequence.

    7. Re:Always do a reboot test ... by SinShiva · · Score: 1

      sync and restart the service, moron

  21. OMG... by Garion911 · · Score: 5, Interesting

    I reported a bug *very* similar to this back in Oct, and only now its coming to light? WTF? I submitted this back in january and it was rejected. Ah well. Here's my page on it: http://garion.tzo.com/resume/page2/bind.html

    --
    Slashdot is like Playboy: I read it for the articles
  22. Re:At least someone agrees that BIND 9 had issues. by Anonymous Coward · · Score: 1, Informative

    Recent versions of BIND (8+) are not terrible to administer

    Try configuring dynamic DNS through nsupdate with a shared secret.

    If you have an NS key, you can specify the key on the command line, or you can store the key in a file, and pass the filename.

    The former is a security risk (as anyone running 'ps' can see your key). The latter? Well, someone decided that it would be a good idea to hard code metadata in the filename (even though the same metadata must be present inside the file too.) Oh, and you need two files, even though it's only using one. Oh, and you need to name the key the same as the zone in your named.conf.

    Considering that I've only ever seen that level of idiocy from first year comp-sci majors, I have to wonder at the technical competence of the people in charge of writing BIND.

  23. Average User by zonker · · Score: 0

    Does your average user have anything to worry about here? Or is this really only a concern for businesses that run their own DNS servers?

  24. Re:I have my own "patch", called a HOSTS file... a by ShakaUVM · · Score: 1

    Your post reads like you'll ask for $20 to show people how THEY TOO CAN SET UP A .HOSTS FILE.

    Just saying.

    Also, your approach is stupid because I like to use the internet.

  25. There's no place like 127.0.0.1 (click) There's no by Nefarious+Wheel · · Score: 1

    Don't forget to set your hosts file to read only. There's bastards out there who will rewrite it for you. Ads. I have a huge hosts file too. But it's mostly for homing out annoyances. Tip: Use Notepad++ for editing your hosts file instead of standard Notepad. The former preserves the lack-of-extent Hosts requires. The latter adds .txt, and you're stuck shuffling file names around. Nice little editor, too.

    --
    Do not mock my vision of impractical footwear
  26. iptables to the rescue by kju · · Score: 5, Informative

    For a quick "fix":

    iptables -A INPUT -p udp --dport 53 -j DROP -m u32 --u32 '30>>27&0xF=5'

    Will block (all) dnsupdate requests.

    1. Re:iptables to the rescue by noidentity · · Score: 1

      For an even quicker fix (works for any vulnerability):

      disconnect network cable(s)

    2. Re:iptables to the rescue by discogravy · · Score: 1

      that blocks all updates, including legit updates. If you're running a server that needs to process non-malicious updates, your best bet is to run a hidden-master/public-slave combination of servers (the attack doesn't work on slave zones).

    3. Re:iptables to the rescue by kju · · Score: 1

      I wrote that it blocks all updates.

  27. It's because it works, & I believe in every wo by Anonymous Coward · · Score: 0

    See subject-line, & "just sayin", right back @ ya... because, it works, "exactly as advertised" with a 100% free price (especially considering I am not selling a thing & you all have one already, lol).

    My approach isn't stupid in regards to that. Free? That's a "pretty good price", wouldn't YOU say? And, you're also FREE to customize it, & thus, YOUR PERSONALIZED VERSION OF A CUSTOM HOSTS FILE, JUST GOES ALONG WITH YOUR PERSONALIZED SPED UP & SAFER VERSION OF THE INTERNET... &, just as YOU see fit & like, easily. Notepad.exe for instance? My gosh - lol, just "does wonders" here, on this account... lol!

    (Plus, using HOSTS files makes me FAR faster online, by double just by blocking adbanners (javascript on the rest helps too, IF it is not demanded for full function), as people will attest to that much by the truckload, go to say, mvps.org & see their forums on that note, as 1 example... & it makes me FAR SAFER too).

    ALL, from a simple text file no less that you already have as long as you have a BSD derived IP stack, & you most likely do, & that YOU can completely control + customize to your liking, yourself, easily. So can anyone else, for free, same bennies, as long as you can read english & use notepad.exe (in Windows that is on the latter).

    Put it this way -> I'll let others speak for me, on this account, instead, via these evidences thereof:

    Even "security guru" Oliver Day @ SecurityFocus.com sees using HOSTS as a good thing for added layered security AND MORE SPEED ONLINE -> http://www.securityfocus.com/columnists/491

    AND?? So do folks like "SpyBot Search & Destroy" also (since their app populates not only the HOSTS file, but, also files like Opera's Filter.ini, FireFox's block lists, & IE Restricted Zones also, for LAYERED SECURITY (this is the trend & recommended practice by security folks by the by, myself included))

    Hey - Even this slashdotter, sootman, uses one & made many interesting points that support his usage of a HOSTS file, from mvps.org, here -> http://tech.slashdot.org/comments.pl?sid=1300193&cid=28677363

    "Also, your approach is stupid because I like to use the internet." - by ShakaUVM (157947) on Wednesday July 29, @12:21AM (#28862259) Homepage

    QUESTION: How does going almost double as fast and safer make you not be able to use the internet?

    (Thanks for your answer!)

    Aha, this "epiphany/revelation" just struck me... lol:

    You are merely a reply from, no doubt, a webmaster worried about page adbanner hits, or an ads server marketing man, lol... ok, to that? I can only say, this:

    ----

    The-Next-Ad-You-Click-May-Be-a-Virus:

    http://it.slashdot.org/story/09/06/15/2056219/The-Next-Ad-You-Click-May-Be-a-Virus

    ----

    That's for readers' reference... & I am certain they too, realize you are either a malware maker/botmaster/hacker-cracker/spyware-virus-rootkit maker, or "money man online" (Both it seems, are profiting by the misfortunes of others basically, by possibly infecting them... and yet making monies from them also for pageviews & adbanner hits...? A good 'hosing' of the customer, & From BOTH ends (literally & figureatively)).

    Time for enough of that, I think.

    APK

    P.S.=> I'll gladly discuss any of this & add to that above too... that's just for starters on this "antiquity" item, being EXTREMELY useful, TODAY, & for better security AND BETTER SPEED, online, today (reliability too it looks like from this article) - & I'll do so, because I love this topic + know it actually works, & WELL!

    On this? Hey man, I am, truly, "The LORD OF HOSTS", on the subject of HOSTS files, so glad to entertain any debate on them... apk

  28. Re:I have my own "patch", called a HOSTS file... a by hairyfeet · · Score: 3, Insightful

    Sounds like a lot of work when you can just run Treewalk DNS and be done with it.It is fast, uses very little resources (mine is using 5Mb ATM) and never gives a bit of trouble.

    --
    ACs don't waste your time replying, your posts are never seen by me.
  29. 0 is smaller & F A S T E R, than 127.0.0.1... by Anonymous Coward · · Score: 0

    Using 0, as I do, is F A S T E R & more efficient than using 127.0.0.1 though (your other points are good - mine's been not only WRITE protected, but also ACL protected too (keep THAT in mind, & use NTFS)).

    I can prove that to you, via you doing something as simple as loading your HOSTS into a LISTBOX (smaller one, then larger ones, or even a converted blocking address one I go into next) or using a std. compiler's language to do the File Open/Read/Close cycle, using a loop (+ a hi-resolution multimedia timer registered with the system to time it)... you can prove it, yourself, if you code.

    My file has 654,000++ entries in it (200 are hardcoded favs, rest are blocked adbanner servers for speed & more security, along with KNOWN bad sites (I can supply sources if you wish, all reputable)).

    Using 0, as my BLOCKING IP ADDRESS (vs. adbanner servers or known bad sites), it is only 14mb in size!

    Next - going on to 0.0.0.0 instead, though smaller than 127.0.0.1, gets you to 18mb in size on my file...

    Using 127.0.0.1 though, the loopback adapter? It uses some CPU afaik, because of what it is (& I am pretty sure 0 &/or 0.0.0.0 are like the NUL port in DOS, pure nada, no cpu usage or not as much), AND, it is larger by far, hitting 20mb on my file (with as many line entries, just converted via a program I wrote for that here, that also removes duplicates from it & pings my favs to keep them current).

    Larger files? SLOWER, period... even when accounting for the 4kb sweeps/passes the memmgt/caching/filesystem/disk drivers utilize, because my using 0 vs. larger blocking IP addresses of 0.0.0.0 or 127.0.0.1 makes for shorter lines in a HOSTS file... meaning MORE OF IT GETS PICKED UP, per PASS/SWEEP, each sweep/pass... more mileage, more power, & even more safety. HOSTS are great for it, but doing 0 based IP address ones for blocking only makes them, the BEST they can TRULY be.

    APK

    P.S.=> I'd also think that since 0 hex = 0 decimal, that the decimal-to-hex & vice-a-versa that goes on shouldn't be necessary on IP addresses like 0, because if you ping a 0 blocked IP in your HOSTS file, you get 0.0.0.0 back though, so not sure on this much, though it might be a GOOD idea for design (127.0.0.1 gets converted & so does 0.0.0.0 iirc, but doing it for 0? Not needed) you save on CPU here & storage too, plus speed gains due to lack of that... LESS IS MORE, & "0"? Accept NO substitute, lol... apk

  30. Will CentOS 4 be updated? by inject_hotmail.com · · Score: 1

    Does anyone know if CentOS 4 will have an update for BIND to ver 9.4.3-P3, 9.5.1-P3 or 9.6.1-P1?

    1. Re:Will CentOS 4 be updated? by Anonymous Coward · · Score: 0

      http://www.durval.com.br/RPMS/el4/bind/

  31. Why waste CPU cycles on that vs. HOSTS though? by Anonymous Coward · · Score: 0

    Why waste CPU cycles running those, when a HOSTS file does the job & users have one already, PLUS for FAR LESS COSTS cpu-wise, software-wise, etc. et al (takes zero cpu cycles, as it is not a program, but more or less a guard-filter & speed upper for favorites, that you already own too).

    "Sounds like a lot of work when you can just run Treewalk DNS and be done with it.It is fast, uses very little resources (mine is using 5Mb ATM) and never gives a bit of trouble." - by hairyfeet (841228) on Wednesday July 29, @01:11AM (#28862507)

    Sure, that might work & there are many alternate local DNS servers & such one can use, but per my subject-line above? Well... that & my p.s. explain my stance on it. I go faster & safer, using a little text file & an editor... it's THAT simple, & inexpensive (costs & cpu cycles wise + RAM usage possibly)...

    Right now? Well... I just do NOT trust the Domain Name System like I used to, especially because of articles like this one. That includes BIND, & really, any others too. Sometimes, yes, I have to use them, even with a HOSTS file, but I minimize that, hugely & use the ones that patch first.

    APK

    P.S.=> Plus, seeing all this DNS poisoning, redirections, & other shenanigans such as Dan Kaminsky found last year/this year, or, this article's points too? No thanks... no offense intended, but, no thanks! apk

    1. Re:Why waste CPU cycles on that vs. HOSTS though? by erikdalen · · Score: 1

      You should really read up on data structures, using a hash map which I guess most DNS-servers use is a LOT faster than searching through a hosts file.

      --
      Erik Dalén
    2. Re:Why waste CPU cycles on that vs. HOSTS though? by the+kings+jokwers · · Score: 0

      well that is funny because when i use a hosts file i run faster, i do not get viruses or unwanted ad banners witch infect a lot of computers. but if you wish to get infected by viruses and Trojans then by all means keep doing what you are doing because i am going to use a hosts file in stead of using a DNS-servers. witch misdirect you to a file you do not want or to a virus or Trojan horse. so by all means keep infecting your self honestly i do not mind one bit. because i will just walk by and chuckle (LOL)

    3. Re:Why waste CPU cycles on that vs. HOSTS though? by Anonymous Coward · · Score: 0

      So much cluelessness in one post.

      Oh yeah... (LOL)

    4. Re:Why waste CPU cycles on that vs. HOSTS though? by the+kings+jokwers · · Score: 0

      the only one that is clueless is you. why not try the APK hosts file you might find out that it works. but i know you will not use the hosts file because you are too chicken, witch in my book constitute you as a loser. but only losers make accusations about things they do not know. so why don't you think before you talk about something you do not know. OH YEAH......(LOL)

  32. Re:I have my own "patch", called a HOSTS file... a by shentino · · Score: 1

    Any ISP's DNS that mucks about with NXDOMAIN is by definition not standard.

  33. Re:0 is smaller & F A S T E R, than 127.0.0.1. by shentino · · Score: 1

    Is it faster for 0.0.0.0 to give you nothing or for 127.0.0.1 to give you a connection refused?

  34. Your point is.... what? by Anonymous Coward · · Score: 0

    See subject line - are you talking about OpenDNS, or something else...?

    (If about OpenDNS - Well, I didn't say they were 'standard' by any means, if so, show us where I did please, thanks... & - What I like about them, for what little I use them for anyhow, is that when Dan Kaminsky found the hassles in BIND last year/this year? They were patched, a.s.a.p.)

    IF that is what you're referring to... that is. I must admit, I am not really sure what you mean here or in regards to what...

    APK

    P.S.=> I'll be awaiting your reply, & Thanks for your time... (but, if you were not addressing me, & you did so by accident (which happens)... then that's cool, forget about it)... apk

    1. Re:Your point is.... what? by shentino · · Score: 1

      Just like I said in my post, I'm talking about ISPs (lookin at YOU charter...) that supply a malicious DNS server.

  35. The end result is the same (you don't get there) by Anonymous Coward · · Score: 0

    See subject-line, & rinse/lather/repeat...

    APK

    P.S.=> Because 127.0.0.1 is the "loopback adapter", that means it is 'doing something', even if it only points to "yourself"... it is a "loopback" mechanism. Processing occurs. Afaik? 0 & 0.0.0.0 are like the NUL device in DOS - nowhere, a waste bucket... no processing needed for that, not really.

    Using 0 though? Hey, big deal, even IF you are running a webserver (because this causes some minor err msgs on some of them & some config file work can clear that or errmsgs (inconsequential ones really) & most folks don't anyhow, run Apache or IIS or whatever @ home because to do a 'real job' of it, you need a commercial account usually, or they kill you on bandwidth & brick your site, if not eventually)...

    0 doesn't do as much processing on disk or as a loopback address either (& iirc, neither does 0.0.0.0 since 0 equates to that but makes for a 25% less sized HOSTS file, & thus, it is faster on disk into memory too because of that & 0, if you think about it, vs. 0.0.0.0 or 127.0.0.1 doesn't even really require a decimal-to-hex conversion really since 0 decimal = 0 hex... that'd be nice to see in the IP stack though because of efficiency if not there already though)! apk

  36. Re:I have my own "patch", called a HOSTS file... a by rs79 · · Score: 1

    " Your post reads like you'll ask for $20 to show people how THEY TOO CAN SET UP A .HOSTS FILE "

    Still cheaper than a $35 domain from Verisign.

    --
    Need Mercedes parts ?
  37. I'm no ISP/BSP, & not w/ charter, but... by Anonymous Coward · · Score: 0

    You DO "hear tell" of what you state though... especially the past couple years, & yes, here on this website.

    (I see what you mean now, I thought you meant ME, lol... or, OpenDNS!)

    I hear some of what they do is redirect banner requests or search filtering (even OpenDNS does the latter, iirc, via opendnsguide.com), but don't QUOTE me on this much, it is only operating on memory (yes, lol, more than "640K: ALL A BODY NEEDS!", lol), so the details are a bit dim on the exacting details of what little I recall... why?

    I rarely really USE DNS servers, even the non-ISP/BSP ones (much less my ISP/BSP's, which are ok afaik) like OpenDNS... because of HOW I use my HOSTS file in addition to knowing my regular "surfing patterns"... as far as hardcodes, & I am certainly NOT resolving many adbanners, lol, this is sure (I go faster this way, I pay for my linetime, I want ALL of it) & I am not hitting bogus sites, because I keep this file up, daily ESPECIALLY vs. that much.

    APK

    P.S.=> HOSTS files, & OpenDNS do the job for me (the former? Probably a GOOD 95% of the time & F A S T, & as efficient as possible, per the format, layout, & placement of it I use)... apk

  38. Re:At least someone agrees that BIND 9 had issues. by rs79 · · Score: 2, Informative

    " Older version were *really* nasty, and had a data file format so complicated... "

    Rememeber that this was a product of the early 1980s; Brian Reid, Director of Digital Equipment Corporation's Network Systems Laboratory ("decwrl.uucp") hired a kid, Paul Vixie, to take the buggy Berkley B-tree code and turn it into something resembling professional software. At the time even C was not even close to ubiquitous, Assembler was though and in fact the great majority of code written for the early microprocessor based systems of that era was written in assembly.

    So it should not be any great shock that bind config files looked like assembly code, or that the later versions looked like C.

    Frankly I found the earlier bind config files much easier to use, and the djbdns config files even easier (once you get used to them) to use, and (much) more importantly, you can write a program to manipulate these datum very easily. It's ugly and complicated with bind data files of any version.

    --
    Need Mercedes parts ?
  39. Modded down? Why?? At least say why cowards... by Anonymous Coward · · Score: 0

    See my subject-line above, because the TRUE "anonymous cowards" are the ones with the mod points who mod others down, but say nothing as to WHY specifically... &, if you're going to mod my post down, won't you @ least show the "intestinal fortitude" to give reasons why I am in error (I am not), or what you disagree with @ least? Thanks for your time (even a detractor's time, because you MAY have points that are reasonable, which would look better than just modding me down for no reason given, I would think @ least).

    APK

    P.S.=> Ah, but then? Sometimes?? Perhaps I expect "too much"... lol, "TOO EASY"... apk

    1. Re:Modded down? Why?? At least say why cowards... by Anonymous Coward · · Score: 0

      I suspect you were modded down because you are grossly off-topic. This is a news story about a vulnerability in an open-source DNS server, not what kind of retarded Windows configuration 'APK' is using.

  40. Still using BIND...? by bagsta · · Score: 1

    Come on people, still using BIND? Why don't you use djbdns? It's easier to use and has a guarnatee!!!

    --
    Until the skies turn blue...
    Until the air of freedom strikes us...
  41. Re:No need to restart bind after updating using yu by palegray.net · · Score: 1

    While this is true for CentOS (RHEL) and Debian-based distros, it's not universally true for others.

  42. Try alternatives by frn123 · · Score: 1

    There are excellent alternatives to bind.
    For example, i have been using nsd for years.
    Super easy to configure. Lacks recursive
    resolver tho..

    http://www.nlnetlabs.nl/projects/nsd/

  43. Smug by TheLink · · Score: 3, Funny

    Smugness to spare? My smugness was overflowing more than BIND9 buffers.

    Great opportunity to vent some smugness today :).

    --
  44. Re:god they should learn programming by gd2shoe · · Score: 3, Insightful

    It could have been worse (and no, I haven't read the article yet). Failing an assertion means that they actually wrote an assertion that did it's job. It's impossible to know without reading the code, but this might have been a remote code execution exploit if they hadn't.

    --
    I won't join Slashcott. OTOH, If Beta goes live, I just won't be back until it's fixed. Sorry Dice.
  45. Re:god they should learn programming by rolfc · · Score: 2, Informative

    I am already updated. Thanks to Debian.

  46. Poor coding by julesh · · Score: 2, Interesting

    Why on earth is BIND shipping with assertions that cause the entire server to exit when they fail? They should just cause processing of the current request to exit.

    1. Re:Poor coding by Ethanol · · Score: 1

      BIND 9 has had a lot of DoS vulnerabilities because of its many asserts. (Addressing this is a goal of BIND 10, actually.) But BIND 9 has had, as far as I know, zero remote code execution vulnerabilities. So the asserts are doing their job.

  47. Re:At least someone agrees that BIND 9 had issues. by MrMr · · Score: 1

    BIND is not a typical Linux application. It was developed at Berkeley and shipped with BSD Unix, and later also with Windows.
    Not a very clever bit of trolling.

  48. Master for "localhost"? by sa3 · · Score: 2, Interesting

    You may hide your master DNS servers but your slaves are probably still master for "localhost".

    1. Re:Master for "localhost"? by DaemonDazz · · Score: 1

      +1 spot on

  49. duuuuude by Anonymous Coward · · Score: 0

    dude please tell me you have a website or somethin coz that stuff is gold info & i totally dont get why they mod u down ether -> probly scared of the truth that hosts is FAST like you say because then they lose money on all ther expensive dns admin stuff if everybody jsut uses hosts

    1. Re:duuuuude by Anonymous Coward · · Score: 0

      "dude please tell me you have a website or somethin coz that stuff is gold info" - by Anonymous Coward on Wednesday July 29, @05:14AM (#28863689)

      Check THIS out then, because it has a LOT more that can benefit you ->

      ----

      HOW TO SECURE Windows 2000/XP/Server 2003 & even VISTA, + make it "fun-to-do", via CIS Tool Guidance (& beyond)

      http://www.tcmagazine.com/forums/index.php?s=87203c9d6d4117d11f30ee4e89cf27d4&showtopic=2662

      ----

      Other seeing the same results as I have, 2++ yrs. worth so far iirc on this fellow's part, after doing that guide of mine in the URL above? Ok:

      ----

      http://www.xtremepccentral.com/forums/showthread.php?s=26a647f959425ebbbb85586b0da252e0&t=28430&page=3

      "Its 2009 - still trouble free! I was told last week by a co worker who does active directory administration, and he said I was doing overkill. I told him yes, but I just eliminated the half life in windows that you usually get. He said good point. So from 2008 till 2009. No speed decreases, its been to a lan party, moved around in a move, and it still NEVER has had the OS reinstalled besides the fact I imaged the drive over in 2008. Great stuff! My client STILL Hasn't called me back in regards to that one machine to get it locked down for the kid. I am glad it worked and I am sure her wallet is appreciated too now that it works. Speaking of which, I need to call her to see if I can get some leads. APK - I will say it again, the guide is FANTASTIC! Its made my PC experience much easier. Sandboxing was great. Getting my host file updated, setting services to system service, rather than system local. (except AVG updater, needed system local)

      ----

      Nuff said, enjoy it... IT ACTUALLY WORKS (whereas other solutions like antivirus/antispyware clearly do not, or not as well (inclusive of false positives or just plain missing many threats, especially those that come thru the webbrowser, which is MOST of them today, via the harbinger of doom itself, javascript).

      ----

      "& i totally dont get why they mod u down ether -> probly scared of the truth that hosts is FAST like you say because then they lose money on all ther expensive dns admin stuff if everybody jsut uses hosts" - by Anonymous Coward on Wednesday July 29, @05:14AM (#28863689)

      You're probably EXACTLY right, & not just from the folks who do DNS servers... I agree!

      Thus To quote Ozymandias from "The Watchmen" once more:

      "So I resolved to apply antiquities teachings (usage of custom malicious site &/or adbanner blocking HOSTS files) to the world, today, & so began my conquest: Conquest, NOT OF MEN, but, of the evils that beset them - Fossil Fuels (antivirus resident), Oil (antispyware resident), Nuclear Power (VM for security layers), are like a drug, & YOU GENTLEMEN, along with foreign interests (RBN, etc. et al), are the pushers..." - Adrian Veidt (Ozymandias), THE WATCHMEN

      You have a STRONG possible point... no doubt about it!

      (HOSTS files usage CAN & DOES affect a LOT of those items I list in my Ozzy quote (because running antivirus/antispyware/or a VM resident's FINE for "noobz" & I even recommend it in that guide URL of mine, but, once you KNOW WHAT YOU'RE DOING? You don't need to keep them resident burning CPU cycles, memory, & other forms of I/O, period)

      Fact is - I've been doing it for 7 months now, NOT A SINGLE INFESTATION... not one! Just doing what is in the rest of my HOW TO SECURE Windows 2000/XP/Server 2003 & even VISTA, + make it "fun-to-do", via CIS Tool Guidance (& beyond) url guide above...

      It can also adversely affect webmasters looking for adbanner vi

    2. Re:duuuuude by the+kings+jokwers · · Score: 0

      keep going APK you are doing a good job. do not let these naysayers get you down. keep going

    3. Re:duuuuude by Anonymous Coward · · Score: 0

      man ure so deep you relly sshould make a blog or a twitter or something

      i hope evry1 woud use HOSTS instead of crappy slow and insecure dns servers then the internet would be a better place.

    4. Re:duuuuude by flibuste · · Score: 1

      Duuude, by the time you setup your host file for all the sites you visit, the Internet age will be gone....Talk about "FAST".

  50. roflcopters by justinlee37 · · Score: 1

    So, basically, the program can be crashed by a specially-crafted malicious update package, and the designers of the program are asking you to update the program in order to shield yourself from exploitation by updates.

    I think there's a joke in there somewhere. Anybody want to give it a shot?

  51. Re:There's no place like 127.0.0.1 (click) There's by smoker2 · · Score: 1

    Tip: Use Notepad++ for editing your hosts file instead of standard Notepad. The former preserves the lack-of-extent Hosts requires. The latter adds .txt, and you're stuck shuffling file names around.

    No it doesn't. Why do you lie ?
    If you create a new file it will append .txt . You can open the existing hosts file by right clicking and selecting "open with" and then choose notepad. It doesn't append .txt to an existing file name.

    I don't generally care anyway, as I can vi /etc/hosts which is much quicker than trying to remember where MS hid the file on their OS.

  52. Why not ? by bytesex · · Score: 1

    Time to let go of that ancient rule that ports under 1024 are root-only.

    --
    Religion is what happens when nature strikes and groupthink goes wrong.
  53. Re:It's because it works, & I believe in every by ShakaUVM · · Score: 4, Funny

    My approach isn't stupid in regards to that. Free? That's a "pretty good price", wouldn't YOU say? And, you're also FREE to customize it, & thus, YOUR PERSONALIZED VERSION OF A CUSTOM HOSTS FILE, JUST GOES ALONG WITH YOUR PERSONALIZED SPED UP & SAFER VERSION OF THE INTERNET... &, just as YOU see fit & like, easily. Notepad.exe for instance? My gosh - lol, just "does wonders" here, on this account... lol!

    Are you the ghost of Billy Mays?

  54. Asserts... by LSD-OBS · · Score: 1

    And this is why asserts should *never* go into production builds of any project. It's fine to have asserts in your debug build, but ALWAYS deal with the unexpected case immediately after your assert (which should be compiled out in release mode).

    If you have no way of throwing an error and handling it gracefully back up your call stack (no, you don't always need exceptions for this), then you've done a shit job!

    --
    Today's weirdness is tomorrow's reason why. -- Hunter S. Thompson
  55. Re:It's because it works, & I believe in every by Fizzl · · Score: 1

    May I have your contact information? I would like to hire you next time I need to write a come-on for an item I'm trying to peddle :P

  56. Re:There's no place like 127.0.0.1 (click) There's by jimbob666 · · Score: 1

    Tip: In Notepad.exe if you surround the filename and extension with quote marks (") on your new file it will keep the extension and not append .txt

  57. Re:god they should learn programming by num42 · · Score: 1

    it's not an article but a security advisory. meaning _if_ you run BIND9 somewhere please do read it. ;-)

    --
    "morning is a state of mind ;)"
  58. Calling a HOSTS takes less time than remote DNS by Anonymous Coward · · Score: 0

    A diskdrive accesses around 10ms nowadays& that's FAR F A S T E R than calling on a remote Domain Name Server & getting a URL-to-IP address resolution from one (pinging them alone takes 30-60ms for returns, illustrating some of the "travel time" involved, for example). Even with a std. HDD, you're looking @ a 3-6 fold order of magnitude decrease in time taken to access a HOSTS file, vs. even talking to a remote DNS Server.

    (Mine does so here, FAR FASTER, @ .01ms (since I house my HOSTS file on a Gigabyte IRAM SSD) after altering the DataBasePath Parameter here -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters))

    My time savings right there alone is gigantic vs. using remote DNS servers for URL-to-IP address resolution from a local HOSTS file, & especially for how I have my HOSTS file setup here?

    That certainly doesn't take me 30-60ns... FAR from it/many orders of magnitude less...

    APK

    P.S.=> YOU should really read what Dan Kaminsky's found about DNS servers, as well as about "DNS Poisoning" as well as this very article also (because in case you haven't noticed? Trusting DNS servers, especially lately, isn't the "greatest idea" )... apk

  59. My fav. AC that mods me down is back, lol!. by Anonymous Coward · · Score: 0

    "I suspect you were modded down because you are grossly off-topic." - by Anonymous Coward on Wednesday July 29, @07:12AM (#28864183)

    How so? I mention how using a HOSTS file completely allows me to escape using potentially "poisoned" or otherwise faulty remote DNS servers (especially for my favorite websites, & anyone can do this also, easily).

    ----

    "This is a news story about a vulnerability in an open-source DNS server, not what kind of retarded Windows configuration 'APK' is using." - by Anonymous Coward on Wednesday July 29, @07:12AM (#28864183)

    Right - & my setup allows me to quite often (most times in fact, for how I surf specifically especially, since I hardcode 200 or my fav. websites in my HOSTS file) to dispense with using remote DNS servers altogether - minimizing my traffic to them, & dependence upon them (especially DNS servers that are poisoned or otherwise faulty (OR NOT)).

    APK

    P.S.=> HOSTS files help that way... apk

  60. DNS client cache or diskcache speeds it up more by Anonymous Coward · · Score: 0

    Also - Once my HOSTS file data is in RAM (be it the local diskcache OR the local DNS Client cache service)? I am going @ "the speed of RAM"...

    Which is FAR FASTER than 30-60ms to call out to a remote DNS Server for a URL-to-IP address resolution!

    Plus - again, how I set my HOSTS file up, on a SSD?

    I am F A R Faster on access/seek for the File Open/Read/Close I-O cycle by far (especially since I minimize this by using 0 as my blocking IP address, vs. the longer & slower 0.0.0.0 + especially the 127.0.0.1 "loopback adapter"), with only a .01ms access/seek time & the file read doesn't take 60ms to achieve, far from it, even on the initial read (& once cached? FAR FASTER STILL yet again). Even folks with a std. mechanical HDD only take 10ms or so to access a file, & that alone is 3-6x as fast as calling out to remote DNS servers for URL-to-IP address resolutions also.

    (So much for your "arguments"... &, of course, there is also testimonials from the likes of Mr. Oliver Day @ SECURITYFOCUS.COM who also says he notices that using a HOSTS file has him going F A S T E R online than he did without one too... plus, safer, especially if KNOWN BAD SITES or SERVERS are blocked in a HOSTS file)

    "NEXT...", lol...

    APK

    P.S.=> Following up on what I wrote to you in reply initially, here -> http://it.slashdot.org/comments.pl?sid=1318247&cid=28864643 w/ this additional data... apk

  61. Re:There's no place like 127.0.0.1 (click) There's by Nefarious+Wheel · · Score: 1
    I do not lie. It appends .txt when you save it, not when you open it. Duh?

    Isn't 0.0.0.0 the broadcast address? Likely blocked by your router then. Comma si, comma sa.

    It's generally in c:\windows\system32\drivers\etc

    --
    Do not mock my vision of impractical footwear
  62. Re:0 is smaller & F A S T E R, than 127.0.0.1. by Anonymous Coward · · Score: 0

    Dunno, every time I use 127.0.0.1 all I see is a ton of porn...

  63. Re:I have my own "patch", called a HOSTS file... a by the+kings+jokwers · · Score: 0

    the only thing stupid is not using this host file

  64. Read Mr. Oliver Day of SECURITYFOCUS.COM by Anonymous Coward · · Score: 0

    Per my subject-line above? See this testimonial to HOSTS files effectiveness on increased speed alone (let alone more security by blocking out KNOWN bad sites &/or servers):

    http://www.securityfocus.com/columnists/491

    Resurrecting the Killfile Oliver Day, 2009-02-04

    PERTINENT QUOTE/EXCERPT:

    ----

    "The host file on my day-to-day laptop is now over 16,000 lines long. Accessing the Internet particularly browsing the Web is actually faster now"

    ----

    As the saying goes? "NUFF SAID...", as the REAL 'BOTTOM-LINE' is about results...

    APK

    P.S.=> "NEXT...", lol - apk

  65. Re:I have my own "patch", called a HOSTS file... a by Anonymous Coward · · Score: 0

    Glib Gibbs said it was $15. Just sayin'.

  66. Re:There's no place like 127.0.0.1 (click) There's by MinistryOfTruthiness · · Score: 1

    Notepad doesn't change the names of existing files, but it does seem to like to force the .txt on new files that it creates.

    I don't think 0.0.0.0 is the broadcast address. The only time I've ever seen it used is in combination with a /0 netmask to stand for "all addresses" e.g. 0.0.0.0/0 I believe the broadcast address is generally the last IP in the subnet, so if you're on 192.168.1.0/24, your broadcast would be 192.168.1.255.

    I'm no network guru, so maybe I'm off a bit too, but I think I'm closer. I'm sure others will be more than happy to correct me. :-)

    --
    "I know that every word that man just said is true, because it's EXACTLY what I wanted to hear." -- Space Ghost
  67. who cares... by godrik · · Score: 1

    ... about a security flow in MS DOS nowadays ?

  68. "Learn to know the 'dark side of the force'" by Anonymous Coward · · Score: 0

    "man ure so deep you relly sshould make a blog or a twitter or something" - by Anonymous Coward on Wednesday July 29, @10:35AM (#28866195)

    Heh, thanks... but, well - NOT really: Most ANY network tech or admin even (users with a better password really, because they only USE tools guys like myself, software engineers/coders/programmers write for them to USE) knows about this even...

    So, that "all said & aside"?

    Well - I cannot put it any better than this:

    "Learn to know the dark side of the force and you will achieve a power greater than any Jedi." - Darth Sidious/Emperor Palpatine (last of the SITH)

    http://www.entertonement.com/clips/msydsyxplv--Learn-to-know-the-dark-side-of-the-force-and-you-will-achieve-a-power-greater-than-any-JediStar-Wars-Episode-III-Revenge-of-the-Sith-Ian-McDiarmid-Supreme-Chancellor-Palpatine-

    Jedi's being my "naysayers" here, & whom I strongly suspect, are merely techies &/or network admins/engineers @ best/most... not coders (who ARE the "sith lords" basically, since many of us, like myself, have done THEIR JOBS, and written the code they merely USE)... period!

    APK

    P.S.=>

    "i hope evry1 woud use HOSTS instead of crappy slow and insecure dns servers then the internet would be a better place." - by Anonymous Coward on Wednesday July 29, @10:35AM (#28866195)

    As is, right now, what with Dan Kaminsky's findings on DNS server faults, as well as this article's points (& network solutions being pilfered this week also, & afaik because of DNS poisoning)? They work... & do anyhow, for superior speed, & security online.

    Evidence thereof, per Mr. Oliver Day of SECURITYFOCUS.COM:

    ----

    http://www.securityfocus.com/columnists/491

    RESURRECTING THE KILLFILE:

    "The host file on my day-to-day laptop is now over 16,000 lines long. Accessing the Internet particularly browsing the Web is actually faster now."

    ----

    Since "my word here" is apparently, NOT good enough? You have Mr. Days as well, saying exactly what I have pretty much (& I am fairly sure he has read my security guide also & agrees with my points in it about HOSTS files value for BOTH added speed, AND SECURITY, online today (especially today in the era of the poisoned DNS server, or malicious sites + adbanners))... especially in LIGHT of this article about DNS troubles, AND this one (bad adbanners):

    ----

    IT: The Next Ad You Click May Be a Virus

    http://it.slashdot.org/story/09/06/15/2056219/The-Next-Ad-You-Click-May-Be-a-Virus?from=rss

    ---- ... apk

  69. "The Dark Side of the force is a pathway..." by Anonymous Coward · · Score: 0

    "The Dark Side of the Force is a pathway to MANY abilities, some consider to be... unnatural!" - Darth Sidious/Lord Palpatine, last of the SITH LORDS...

    Or, my 'naysayers' really in THEY essentially being "the jedi"... what I propose here is often beyond their limited "I read it in a manual or a forums & that MUST be the 'only way' or 'best way'" type b.s. they try to pass off as "know-how"... lol! They're merely "users with a better password", who merely USE what guys like myself (who have done their job, & FAR MORE, as a coder/software engineer/programmer as well as network engineer/admin/tech too in my time professionally in this art & science) created for them to USE... & that is about it.

    They're SEVERELY "limited in scope" as to their abilities, period. At least by comparison to coders... by far.

    HOW CAN I SAY THAT? Simple, look @ their suggestions & my replies in rebuttal (I easily shut them down on every point, with proofs or tests they themselves can try even (IF they could code, most of them? Cannot... limited!)

    "You must break thru the fog of lies the jedi have created around you. Let me help you to know the subtleties of the force...Anakin, if one is to understand the 'great mystery' one must understand, ALL OF ITS ASPECTS... NOT just the narrow, dogmatic view of the Jedi: IF you wish to become a wise leader, one must embrace... a LARGER view of the force..." - Darth Sidious/Lord Palpatine, last of the SITH LORDS...

    (Especially in light of this article, plus Dan Kaminsky's findings regarding problems in DNS servers, as well as Network Solutions going batty this week (iirc, & afaik, due to DNS poisoning in part (don't quote me on that though)) PLUS the fact that a HOSTS file does make you go faster, period, to which I also provide not only my own testimony thereof, but that of noted others + others responses here too?)

    Hey - Well... read on:

    "Duuude, by the time you setup your host file for all the sites you visit, the Internet age will be gone....Talk about "FAST"." - by flibuste (523578) on Wednesday July 29, @11:37AM (#28867215)

    Not true, because MANY reputable sources for HOSTS files that already work well, exist, such as the one @ WIKIPEDIA (steer clear of the ones from FRANCE though):

    http://en.wikipedia.org/wiki/Hosts_file

    AND, to further populate it for security? You can use sites like these (excellent for it):

    ZDNet's Mr. Dancho Danchev's weekly blog -> http://ddanchev.blogspot.com/

    SRI -> http://mtc.sri.com/

    & others, such as "Spybot 'Search & Destroy'", which also populates your HOSTS file (plus, Opera's filter.ini, FireFox/Mozilla's internal to browser 'block lists' as well as IE's "restricted zones" too...

    (Stopbadware.org is good too - they're essentially, GOOGLE or partnered w/ them, afaik...)

    APK

    P.S.=> "The Dark Side of the Force is a pathway, to many abilities... some consider to be, 'unnatural'" but, it works for MANY abilities, including being faster & safer online (& this thread has plenty of evidence from myself + others to that effect as proof thereof, such as Mr. Oliver Day from SECURITYFOCUS.COM) but, "Is it possible to learn this power?" & answer is "NOT FROM A JEDI" - the 'jedi' being these 'users with a better password only at best/most' in network techs/network admins, with their LIMITED scope & knowledge in this field (as opposed to the TRUE 'sith', in coders/programmers/software engineers, who invent the tools those same "jedi" MERELY USE, but do not create, themselves, period)... apk

  70. Tested exploit, not that big of a deal by Anonymous Coward · · Score: 0

    I work for a major DNS provider currently doing DNS administration. I have reviewed the current exploit as well as the prior exploit release (that "is" practically the same) as released by John Sutherland originally against multiple versions of Bind 9. While the ACL's do not appear to be respected per the updates requested, which seems to have a lot of people concerned that this will affect their public facing name servers, it does appear that the dynamic update has to be accepted. Hence, you DO need to know the tsig key and then query for the succesfuly updated record before the assertion error will cause BIND to cease running. If anyone can prove me wrong, it would be much appreciated.

    Again, you:

    1) Need to send the dynamic update to an IP that is listening for updates on the target BIND server
    2) You do need to know the correct tsig key to have the update accepted
    3) You do need to query the updated record IN ANY for the assertion error to actually be presented

    Please explain how this is that concerning? Who exactly can immediately guess or can brute force tsig keys for a specific server before IDS or even the human eye notices all the denied update requests coming in?

    This vulnerability should be attributed to its original discover, John Sutherland first off. And secondly, its by no means the end of the world unless someone has more info on this that isn't being disclosed to the public. And no, I do not work for the same company as Mr. Sutherland, I actually work for a competitor for any of you that think this is a shameless promotion. I'm just saying that fair is fair and he did discover it first.

  71. "And now, young jedi? You WILL die..." by Anonymous Coward · · Score: 0

    Per my subject-line above, & this quote from you:

    "You should really read up on data structures, using a hash map which I guess most DNS-servers use is a LOT faster than searching through a hosts file." - by erikdalen (99500) on Wednesday July 29, @04:27AM (#28863433) Homepage

    Especially considering THIS VERY ARTICLE is about their faultiness (dns server hassles & bugs)? Hey... lmao, @ that quote, from you above! Why/How?

    Simple: Especially considering the facts in my other 3 replies to you, as well as Kings Jowkers success in using a HOSTS file too, which was in reponse to that which I quote above (plus Mr. Oliver Day's of SECURITYFOCUS.COM who also recommends HOSTS files for better speed & security too as I have)?

    ----

    About HOSTS files loads from disk speed, even SSD's as I do (even faster), vs. time taken for calls to remote DNS servers (many times faster how I do it using a CUSTOM HOSTS FILE, period, without the possible poisoning or misdirects that DNS servers obviously have been showing, PER this article & others)

    http://it.slashdot.org/comments.pl?sid=1318247&cid=28864643

    ----

    On DNS local client cache, OR, even a diskcache subsystem, speeding up what I noted in my url just above this one (even moreso):

    http://it.slashdot.org/comments.pl?sid=1318247&cid=28865197 (DNS local client cache, OR, even a diskcache subsystem, speeding up what I noted in my url just above this one, even moreso)

    ----

    Mr. Oliver Day's successes in gaining more SPEED using hosts files (as well as better LAYERED security too):

    http://it.slashdot.org/comments.pl?sid=1318247&cid=28865727

    ----

    As well as "sootman"'s (he is a member here who uses a HOSTS file successfully) take on HOSTS file (he is also a user here that uses one, the model from mvps.org, whose forums you MAY wish to look @ also, in regards to successes folks have had using HOSTS files for more speed, and security, online today (especially today, in the era of the poisoned DNS server, &/or bogus adbanner ads + bad websites)):

    ----

    http://tech.slashdot.org/comments.pl?sid=1300193&cid=28677363

    ----

    Then, there is the issue of bogus adbanners (which if you block them? You go faster online, by almost DOUBLE no less, & safer by far also, per the above):

    ----

    IT: The Next Ad You Click May Be a Virus:

    http://it.slashdot.org/story/09/06/15/2056219/The-Next-Ad-You-Click-May-Be-a-Virus?from=rss

    ----

    ?

    Given ALL of those?

    Well - You MUST consider the findings of Dan Kaminsky & holes in DNS he has found, as well as "DNS poisoning" itself, AND THIS VERY ARTICLE's CONTENT here today in which we are replying, as well...

    APK

    P.S.=> Keep trusting DNS servers alone, because as this article notes? They are faulty, & they ARE under attack... & you get, what you get (like this article shows, as just 1 single example, for securities' sake - let alone the speed gains HOSTS files give you, along with being able to reach your fav. sites, even IF your DNS goes down to exploits such as this article shows)... apk

  72. TCP or UDP? by yuna49 · · Score: 1

    I can't tell after reading the ISC release and various other documents how this exploit takes place. I have a machine with UDP port 53 publicly visible, but TCP port 53 is firewalled off against all IPs except the machines under my control. Is this a UDP or a TCP exploit?

    Someone above posted an iptables rule that applied to UDP port 53. Is that correct?

  73. Ahem: (Cough "bullshit") by Anonymous Coward · · Score: 0

    "Dunno, every time I use 127.0.0.1 all I see is a ton of porn..." - by Anonymous Coward on Wednesday July 29, @09:30AM (#28865293)

    Ahem: (cough - "BULLSHIT!" - cough!)

    (Are you running your own Pr0n server or something?)

    Try 0 or 0.0.0.0 instead, as "blocking IP addresses" in your HOSTS file, vs. bogus sites (simply because they're smaller, & more efficient than 127.0.0.1 is anyhow)...

    APK

    P.S.=> Still, just based on the rest of your replies here? To be BLUNT about it?? Well, I think you are full of it - Well, unless YOU have something very odd going on in your system, as is, already, beforehand (which is, quite possible)... apk

  74. No, I am not and you're OFF-TOPIC by Anonymous Coward · · Score: 0

    See my subject-line above...

    APK

  75. Re:There's no place like 127.0.0.1 (click) There's by kayditty · · Score: 0

    the broadcast address is the number where all bits of the host segment are one. a subnet isn't necessarily an "octet," especially in classless systems. 0/0 is interpreted by many network stacks in the same way as localhost, but it's the network or "network discovery" address for the internet IPv4 space.