Bind dns amplification attack

Grant Taylor gtaylor at tnetconsulting.net
Tue Mar 28 17:02:23 UTC 2023


On 3/28/23 10:48 AM, Matus UHLAR - fantomas wrote:
> If your server has authroritative zones for internal use, yes, in such 
> case allow-query is good idea.

The server that I first set this on had a secondary copy of the root 
zone for my systems use.  I ended up adding additional restrictions to 
prevent the world from querying it in addition to the public zones that 
are allowed to be queried by the world.



-- 
Grant. . . .
unix || die

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4017 bytes
Desc: S/MIME Cryptographic Signature
URL: <https://lists.isc.org/pipermail/bind-users/attachments/20230328/ea5bdb67/attachment.bin>


More information about the bind-users mailing list