[rescue] Tricking DNS
Kevin Loch
rescue at sunhelp.org
Mon Oct 22 10:25:13 CDT 2001
"Loomis, Rip" wrote:
> *Don't* use the BIND that's included with Solaris, whatever
> you do, unless you have someone holding a gun to your head.
> Historically, it has taken Sun anywhere from 4 to 24 weeks
> to get patches out for "their" BIND implementations--and that's
> an unacceptable window of vulnerability. As with Sendmail,
> if you need the functionality then use the latest stable
> and secure release, rather than sticking with the Sun version.
That is exactly what I meant. FWIW, don't use Solaris Sendmail,
FTP, or any publicly accessible service. It is good engineering
practice to compile external services yourself from latest good
source code (not counting beta/pre-release of course).
KL
More information about the rescue
mailing list