作者litjoejoe (joejoe)
看板FreeBSD
标题[问题] BIND 9.4.2 弱点如何修正?
时间Wed Dec 12 21:20:53 2007
请问一下版上的大大,最近在玩一套弱点扫瞄的软体,
我用他来扫我的DNS,发现都会出下以下3个弱点,就算升级到BIND 9.4.2
还是一样,找了网路上的文章,都没有说怎麽避免,不知道有没有大大知道的
1.DNS Cache Snooping
Description:
Remote DNS server is vulnerable to Cache Snooping attacks.
Recommendation:
Review the above mentioned paper for an overview of the implications
and recommended solutions to the DNS Cache Snooping attack. Ensure you
have the latest version of your DNS Server although this vulnerability
may be the result of configuration error.
The DNS Cache Snooping article contains a safe BIND configuration
that restricts recursive requests to trusted clients. Ensure DNS
servers that service untrusted networks only provide authoritative
data and do not respond to recursive requests.
2.BIND Allow Authors Request
Description:
BIND versions 9.0 and later could allow a remote attacker
to obtain sensitive information.
Recommendation:
http://www.isc.org/products/BIND/
3.BIND Allow Version Request
Description:
BIND (Berkeley Internet Name Domain) servers support
the ability to be remotely queried for their version numbers.
Recommendation:
Disable the BIND version query feature.
关於第3点,网路上都是教人填一个版本进去,但要怎麽关掉呢?
--
※ 发信站: 批踢踢实业坊(ptt.cc)
◆ From: 140.138.32.31
※ 编辑: litjoejoe 来自: 140.138.32.31 (12/12 21:21)
※ 编辑: litjoejoe 来自: 140.138.32.31 (12/12 21:22)