[svlug] Bind Vulnerabilities

Todd Lyons todd at mrball.net
Sun Mar 25 22:51:01 PST 2001


Marc MERLIN wrote:

> Typically in a  split DNS setup, you  not only don't want  outside people to
> query  your resource  records for  your intranet,  but you'll  often give  a
> different IP for the same host:

Hmmm, if the DNS is behind the firewall, can you configure it to give
two different sets of answers depending on if the request originates
from internal or external IP's?  In this case, DNS is not on a DMZ and
it's on the same subnet as the other internal machines.
-- 
Blue skies...		Todd
| Get a bigger hammer!   |  PPPoE: the internet for people who    |
| http://www.mrball.net  |  don't want the Internet.              |
| http://faq.mrball.net  |                       --Aaron Lehmann  |




More information about the svlug mailing list