From owner-freebsd-security Wed Jun 26 20:20:26 2002 Delivered-To: freebsd-security@freebsd.org Received: from gw.nectar.cc (gw.nectar.cc [208.42.49.153]) by hub.freebsd.org (Postfix) with ESMTP id 2A81E37B400 for ; Wed, 26 Jun 2002 20:16:15 -0700 (PDT) Received: from madman.nectar.cc (madman.nectar.cc [10.0.1.111]) by gw.nectar.cc (Postfix) with ESMTP id BE36523; Wed, 26 Jun 2002 22:16:14 -0500 (CDT) Received: from madman.nectar.cc (localhost [IPv6:::1]) by madman.nectar.cc (8.12.3/8.12.3) with ESMTP id g5R3GEsE046836; Wed, 26 Jun 2002 22:16:14 -0500 (CDT) (envelope-from nectar@madman.nectar.cc) Received: (from nectar@localhost) by madman.nectar.cc (8.12.3/8.12.3/Submit) id g5R3GE6v046835; Wed, 26 Jun 2002 22:16:14 -0500 (CDT) Date: Wed, 26 Jun 2002 22:16:14 -0500 From: "Jacques A. Vidrine" To: Mark.Andrews@isc.org Cc: security@FreeBSD.ORG Subject: BIND and reconstruction of DNS messages (was Re: FreeBSD Security Advisory FreeBSD-SA-02:28.resolv) Message-ID: <20020627031614.GE46205@madman.nectar.cc> References: <4.3.2.7.2.20020626133115.022a0d30@localhost> <200206270012.g5R0C8m0029482@drugs.dv.isc.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <200206270012.g5R0C8m0029482@drugs.dv.isc.org> User-Agent: Mutt/1.4i X-Url: http://www.nectar.cc/ Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org On Thu, Jun 27, 2002 at 10:12:08AM +1000, Mark.Andrews@isc.org wrote: > Provided you are behind a nameserver you trust that reconstructs > the answer you should be fine. Thanks for this info, Mark. I guess that name server better be running on localhost, or else an agent may be able to spoof DNS messages. > BIND 9 reconstucts all answers (excluding forwarded UPDATES). cool > BIND 8 forwards some and reconstructs others. at random? :-) Cheers, -- Jacques A. Vidrine http://www.nectar.cc/ NTT/Verio SME . FreeBSD UNIX . Heimdal Kerberos jvidrine@verio.net . nectar@FreeBSD.org . nectar@kth.se To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message