nameserver A record hijacking.

Jim Reid jim at rfc1035.com
Thu Jan 24 08:40:05 UTC 2002


>>>>> "Greg" == Greg Robinson <robinson at nospam.no-org.org> writes:

First of all, use a valid email address. The newsgroup is
bidirectionally gatewayed into a mailing list, bind-users at isc.org.
It's very silly and anti-social to supply unreplayable email addresses
in email. And in your case it doesn't prevent spam either.

    Greg> Hi, I would like to know how to prevent nsupdate or any DDNS
    Greg> tool from being able to modify an A record, which just
    Greg> happens to be the nameserver A record, or any other static A
    Greg> record I would really really like to keep.

Take a look at update-policy{} in BIND9.2.


More information about the bind-users mailing list