What to do about HiNet cache poisoning?

Barry Margolin barmar at genuity.net
Wed Apr 24 18:35:26 UTC 2002


In article <aa6k3f$5ff at pub3.rc.vix.com>,
Rob van der Putten  <rob at sput.nl> wrote:
>
>Hi there
>
>
>Mark_Andrews at isc.org wrote:
>
>>         It doesn't unless it is behind a forwarder and the forwarder lets
>>         the bogus data through.  Balliwick doesn't work behind a forwarder.
>
>I removed all forwarders. Same problem.
>I added a bogusdns list to the config. Hope this helps.
>
>Is there any way that I can tell bind to get info on `.',
>`root-servers.net.' and `in-addr.arpa.' only form the root servers and
>from nobody else?
>And how can I tell bind to really ignore info it didn't specificly ask
>for?

What version of BIND 8 are you running?  We were seeing this problem with
8.2.3, but upgrading to 8.3.1 cleared it up unless we were using
forwarding.

-- 
Barry Margolin, barmar at genuity.net
Genuity, Woburn, MA
*** DON'T SEND TECHNICAL QUESTIONS DIRECTLY TO ME, post them to newsgroups.
Please DON'T copy followups to me -- I'll assume it wasn't posted to the group.


More information about the bind-users mailing list