<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Securing HP-UX DNS in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-hp-ux-dns/m-p/3192172#M164986</link>
    <description>BIND is DNS, but DNS isn't BIND...</description>
    <pubDate>Mon, 16 Feb 2004 10:35:05 GMT</pubDate>
    <dc:creator>Paul Cross_1</dc:creator>
    <dc:date>2004-02-16T10:35:05Z</dc:date>
    <item>
      <title>Securing HP-UX DNS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-hp-ux-dns/m-p/3192169#M164983</link>
      <description>We have one DNS server on our network that all the Asian root servers love to send binaries to over port 53.  Hence I have the following 2 questions.&lt;BR /&gt;&lt;BR /&gt;2 Questions:&lt;BR /&gt;&lt;BR /&gt;1)  Is there a way we can secure the DNS server to reject a DNS response with binary code in it?&lt;BR /&gt; &lt;BR /&gt;2)  Is there really some legimate DNS traffic to a BIND server that should be from a root server?  Or in other words, is there going to be any problems if we start blocking this type of traffic.&lt;BR /&gt;&lt;BR /&gt;Michael</description>
      <pubDate>Fri, 13 Feb 2004 16:47:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-hp-ux-dns/m-p/3192169#M164983</guid>
      <dc:creator>Michael_423</dc:creator>
      <dc:date>2004-02-13T16:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: Securing HP-UX DNS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-hp-ux-dns/m-p/3192170#M164984</link>
      <description>Hello Michael,&lt;BR /&gt;&lt;BR /&gt;you might get a useful answer here (a number of experienced UX folks frequent this Linux forum) but if you want to discuss hpux specific details you might be better off over in the hpux forum at&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/familyhome.do?familyId=117" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/familyhome.do?familyId=117&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;All the best,&lt;BR /&gt;&lt;BR /&gt;Martin  &lt;BR /&gt;</description>
      <pubDate>Fri, 13 Feb 2004 17:13:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-hp-ux-dns/m-p/3192170#M164984</guid>
      <dc:creator>Martin P.J. Zinser</dc:creator>
      <dc:date>2004-02-13T17:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: Securing HP-UX DNS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-hp-ux-dns/m-p/3192171#M164985</link>
      <description>1) I properly configured DNS server with BIND 9.2.0 will not allow tranfers of binaries. It will only answer valid requests for name resolution infomration.&lt;BR /&gt;&lt;BR /&gt;2) BIND is DNS DNS is BIND. Two names for the same thing.  &lt;BR /&gt;&lt;BR /&gt;I do not believe you need to do anything to the BIND version from software.hp.com to secure it against this kind of attack.&lt;BR /&gt;&lt;BR /&gt;Do you have any evidence that this has been done to your servers?&lt;BR /&gt;&lt;BR /&gt;In the HP-UX security section &lt;A href="http://forums1.itrc.hp.com/service/forums/categoryhome.do?categoryId=155" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/categoryhome.do?categoryId=155&lt;/A&gt; you will see posts by Berlene Herren. She has posted a number of DNS/BIND security warnings in the past month. Following the instructions there will leave you secure.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Sat, 14 Feb 2004 23:15:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-hp-ux-dns/m-p/3192171#M164985</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-02-14T23:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: Securing HP-UX DNS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-hp-ux-dns/m-p/3192172#M164986</link>
      <description>BIND is DNS, but DNS isn't BIND...</description>
      <pubDate>Mon, 16 Feb 2004 10:35:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-hp-ux-dns/m-p/3192172#M164986</guid>
      <dc:creator>Paul Cross_1</dc:creator>
      <dc:date>2004-02-16T10:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: Securing HP-UX DNS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/securing-hp-ux-dns/m-p/3192173#M164987</link>
      <description>Yes, I realized after my post that you don't need BIND to do DNS. DNS 4.9 was not BIND and Microsoft does it quite nicely without BIND.&lt;BR /&gt;&lt;BR /&gt;Thanks for the correction.&lt;BR /&gt;&lt;BR /&gt;I'm asking HP to move this thread to HP-UX.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Mon, 16 Feb 2004 11:03:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/securing-hp-ux-dns/m-p/3192173#M164987</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-02-16T11:03:08Z</dc:date>
    </item>
  </channel>
</rss>

