iquery and Cybercop Scanner

John jking2019 at my-deja.com
Thu Apr 13 10:17:49 UTC 2000


 I am running BIND 8 patch lvl 5 on a Solaris 2.6 system. When I ran a
recent install of Cybercop scanner it reported the following:

"We suggest you do not compile your name daemon with IQUERY support.
Keeping this support in you name daemon will allot intruders to poll
zone transfers regardless of whether you allow them or not"

Three questions on this:

1. At the version I am running am I still vulnerable. I saw a post on a
bind mailing list saying this was fixed. So is this a false positive.

2. What would it hurt to compile this out?

3. How do I compile it out? Couldnt find a reference detailing the
switche needed for the make.

Thanks

--
-John


Sent via Deja.com http://www.deja.com/
Before you buy.



More information about the bind-users mailing list