LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


View Poll Results: Which one?
djbdns 3 27.27%
bind 8 72.73%
other 0 0%
Voters: 11. You may not vote on this poll

Reply
  Search this Thread
Old 06-16-2002, 04:20 PM   #1
koningshoed
Member
 
Registered: May 2002
Location: South Africa
Distribution: Gentoo
Posts: 103

Rep: Reputation: 15
dns: bind/djbdns


Hallo all

I'm wondering excactly how secure dns is. Someone once told me: "Yea well, unfortunately dns is inherently insecure by design". I would like to know why this is, if anyone can help me.

Also, I now have to choose between setting up djbdns and bind. I already know how the bind configs work (and I don't like it all that much but I guess that is just the way it is).
 
Old 06-20-2002, 12:17 PM   #2
Noerr
Member
 
Registered: May 2002
Location: Dalec, HU
Distribution: Redhat 7.3
Posts: 696

Rep: Reputation: 30
bind 9.2.1 is very, very secure (until they find new exploit
 
Old 06-20-2002, 02:11 PM   #3
koningshoed
Member
 
Registered: May 2002
Location: South Africa
Distribution: Gentoo
Posts: 103

Original Poster
Rep: Reputation: 15
I saw some of the new configuration options - decided it's more familiar and seemingly they implemented a few new security features. Hope they are good. And if not, I've set up a cron job to run apt-get update/upgrade once a day so it'll patch as soon as security patches are released (which it usually is within a day or two).

thanks
 
Old 06-20-2002, 04:31 PM   #4
Noerr
Member
 
Registered: May 2002
Location: Dalec, HU
Distribution: Redhat 7.3
Posts: 696

Rep: Reputation: 30
I'm not sure how you would apply patches, but I always prefer clean install (it's not much slower anyway). I think that all bind 9+ versions aren't really exploitable, and if they are they work as non root
 
Old 06-20-2002, 09:04 PM   #5
ifm
Member
 
Registered: Jun 2002
Location: USA
Distribution: RH7.3 & YDL2.1
Posts: 124

Rep: Reputation: 15
Bind

Ive gone with BIND. After reading both in depth and seeing what exactly djbdns does... I decided to go with BIND instead.

Ive setup two BIND 9 servers, one is referred to as the primary, but only in the sense that its the only machine I have to touch when I do any sort of dns change or update.

I made my own backend ssh secure mirroring setup with zone files and zone records between the primary and secondary. I didnt like the way bind handled zone transfers AT ALL ... and with my firewall setup, it was bein pissy as well.

Right now, I have two fully running dns machines for all domains we own and client authority. And they are working quite well!

One is on a YDL2.1 OS, and the other is RH73. Both are the exact same BIND version as well.

With some scripts Ihave, and dynamic zone creation I do ... BIND seemed MUCH more easier to control in the backend than that 'thing' djbdns. djbdns doesnt seem to follow any standards I can see. Even making up zone entries looks overly complex for what it truly is. And the many command line utilties and many other pieces of 'the guys software' you gotta install as well... guh. I decided to go with the all in one install of BIND.

As a security precaution, I even have both BIND servers running chrooted into a secured folder only the user has access too.
 
Old 06-21-2002, 12:32 PM   #6
koningshoed
Member
 
Registered: May 2002
Location: South Africa
Distribution: Gentoo
Posts: 103

Original Poster
Rep: Reputation: 15
Well, just as an aside, 'the guys software' is some of the best, most stable I've seen in some time. Take qmail for instance, ucspi-tcp, daemontools. I use them all, the whole time. So just be carefull - it may just be his dns server that is not very good.

What did you mean with "I didnt like the way bind handled zone transfers AT ALL ... and with my firewall setup, it was bein pissy as well".
 
Old 08-09-2002, 09:01 AM   #7
Nuts
LQ Newbie
 
Registered: Aug 2002
Location: FRANCE
Distribution: redhat 7.3
Posts: 9

Rep: Reputation: 0
Re: Bind

Hi !

As you seem to know bind quite well, i have a question for u :

how can I set up a DDNS ?

i'm talking about configuring named.conf and finding a SIMPLE
DDNS client !

i give a few precisions :

_ i have a redhat 7.3 with bind 9
_ i have a DNS accessible on the net
_ i want a remote client = an apache server (using DHCP for network configuration ) with a public IP to make update on my DNS

I've already tried to use "dhis" solutions (if you don't know : www.dhis.org ), it seems to me it was unpossible to run with bind 9....
In addition, I don't want a program that would be installed on the DHCP server ( i have no access to this DHCP server).
I don't want to use dyndns or something like that !

so please help me !

thanks

Nuts
 
Old 08-09-2002, 11:52 AM   #8
MartBrooks
Member
 
Registered: May 2002
Location: London
Distribution: Debian
Posts: 388

Rep: Reputation: 31
Fascinating. The forum tells me that I've already voted in this poll.

Can anyone tell me what I voted?

Regards
 
Old 08-09-2002, 12:22 PM   #9
koningshoed
Member
 
Registered: May 2002
Location: South Africa
Distribution: Gentoo
Posts: 103

Original Poster
Rep: Reputation: 15
Do I usderstand you correctly when I state you would like to have some kind of dynamic DNS, but you do not want to install a special program on the dns server?

If you were willing to to that it probably would have been a simple job of finding a program that'll take messages from client machines when they boot up (these would send a message to the DNS server just after they received their ip from the DHCP server stating their dns name and their ip) which will then update the config files for bind and restart bind (well, reload at least). I'm not aware of any such packages though.

If DHCP is configured on MAC addresses though you can be sure that the same machine will *always* receive the same ip. And then there will probably be no need for DDNS. But somehow I get the feeling this is not the case ...

Good luck.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Dns (bind) njdownes Linux - Networking 3 02-28-2005 09:15 AM
What can djbdns, (or any DNS Server/cacher) do for me? Gsee *BSD 32 01-05-2005 07:42 AM
Bind DNS help. mdpolaris Linux - Networking 2 10-28-2004 04:09 AM
Anyone with "djbdns/tinydns" experience?? Trying to learn DNS.. l0f33t Linux - Networking 2 02-04-2004 02:56 AM
DNS/Bind Help yoddy Linux - Newbie 2 06-23-2003 03:52 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:57 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration