From owner-freebsd-security Thu Feb 22 13:44:12 2001 Delivered-To: freebsd-security@freebsd.org Received: from mailhost01.reflexnet.net (mailhost01.reflexnet.net [64.6.192.82]) by hub.freebsd.org (Postfix) with ESMTP id 3683A37B491 for ; Thu, 22 Feb 2001 13:44:10 -0800 (PST) (envelope-from cjc@rfx-216-196-73-168.users.reflexcom.com) Received: from rfx-216-196-73-168.users.reflexcom.com ([216.196.73.168]) by mailhost01.reflexnet.net with Microsoft SMTPSVC(5.5.1877.197.19); Thu, 22 Feb 2001 13:42:13 -0800 Received: (from cjc@localhost) by rfx-216-196-73-168.users.reflexcom.com (8.11.1/8.11.1) id f1MLhuS95301; Thu, 22 Feb 2001 13:43:56 -0800 (PST) (envelope-from cjc) Date: Thu, 22 Feb 2001 13:43:55 -0800 From: "Crist J. Clark" To: Cy Schubert - ITSD Open Systems Group Cc: Michael Richards , freebsd-security@FreeBSD.ORG Subject: Re: Bind problems Message-ID: <20010222134355.K89396@rfx-216-196-73-168.users.reflex> Reply-To: cjclark@alum.mit.edu References: <3A947710.000009.60978@frodo.searchcanada.ca> <200102221507.f1MF7iX45138@cwsys.cwsent.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: <200102221507.f1MF7iX45138@cwsys.cwsent.com>; from Cy.Schubert@uumail.gov.bc.ca on Thu, Feb 22, 2001 at 07:07:24AM -0800 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org On Thu, Feb 22, 2001 at 07:07:24AM -0800, Cy Schubert - ITSD Open Systems Group wrote: > In message <3A947710.000009.60978@frodo.searchcanada.ca>, "Michael > Richards" wr > ites: > > Since the big BIND vulnerability, I checked all my versions of BIND > > to make sure they weren't the 8.2.2 variety. None were. > > > > Most returned: named 8.2.3-T6B Thu Nov 23 19:00:06 EST 2000 > > Which is not supposed to be vulnerable. > > I wouldn't be surprised if your system has already been hacked. > 8.2.3-REL has fixed all known (to ISC) security holes. All previous > versions of BIND are vulnerable. Not precisely true. See everone's favorite ISC page for the details, http://www.isc.org/products/BIND/bind-security.html -- Crist J. Clark cjclark@alum.mit.edu To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message