Restricting zone transfers with IP addresses in BIND DNS Server

by nixcraft | October 12, 2007 at 11:14 pm
217 views | 0 Recommendations | 0 comments

DNS server can be attacked using various techniques such as:


[a] DNS spoofing




[b] Cache poisoning




[c] Registration hijacking




One of the simplest ways to defend is limit zone transfers between
nameservers by defining ACL. I see many admin allows BIND to transfer
zones in bulk outside their network or organization. There is no need
to do this. Remember you don't have to make an attacker's life easier.




Restricting zone transfers with IP addresses in BIND DNS Server

Advertisement

Comments (0)

This story was created over 3 months ago, the comment thread is now closed.

closeSign in to NowPublic

is reporting from