[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] Bind - a better solution?



In a message dated 2/23/01 7:52:49 AM Eastern Standard Time, chris@xxxxxx 
writes:

<<  From:   chris@xxxxxx (Chris Mason)
  I see that Bind 8.2.3 has a reported expoit already, so I am cooncerned
 about the security of this daemon. Is it possible to have named start as a
 user other than root? THat would help significantly.
 
 Chris Mason
  >>

Do you really need to run bind on your machine?

What we do now..after having a few machineshacked into and REHACKED after the 
update..is we have 2 cheapy boxes who ONLY run name services...pointing to 
the raqs......IN the raqs...IF you do pop email, you do need to the MX record 
( Cobalts MX record is a MX + modifications to the sendmail user table !) and 
it works like a charm

there is only one user on the dns machines, and who cares if they hack 
in..let them...we dont care...worst case is we take one machine ofline, 
rebuild it and the other does the 2ndary dns....

but that is only 2 dutch guilders