Re: BIND security question

2000-01-01 Thread aphro
On Fri, 31 Dec 1999, hypnos wrote: hypnos >how does this work? because only superuser can hypnos >bind to privileged ports (<1024) right? so does hypnos >named start as root, then switch to the user hypnos >specified? hypnos > hypnos >i may look into changing my named to run as hypnos >other than

Re: BIND security question

1999-12-31 Thread hypnos
On Fri, 31 Dec 1999, Robert Varga wrote: > > I installed the Debian package for BIND, and I just checked and it does > > appear > > to be running as root :( > > > > I will have to read the docs to determine if I can change that without > > compiling it myself. > > Just append >-- -u named

Re: BIND security question

1999-12-31 Thread Robert Varga
On Thu, 30 Dec 1999, Pollywog wrote: > > On 30-Dec-1999 Onno wrote: > > At 04:16 PM 12/28/99 -, Pollywog wrote: > >> > >>On 28-Dec-1999 root wrote: > >> > >>Was this someone trying to find out which BIND I am running? > >>> > >>> Unusual System Events > >>> =-=-=-=-=-=-=-=-=-=-= > >>> Dec

Re: BIND security question

1999-12-30 Thread aphro
i run a chroot'd bind, so everything has to be in the same place .. so for me everythign is in /var/named nate On Thu, 30 Dec 1999, Pollywog wrote: pollyw >I installed from a Debian package, I did not compile my own. Debian puts the pollyw >files in /etc/bind now, not the former place, /var/na

Re: BIND security question

1999-12-30 Thread Pollywog
I installed from a Debian package, I did not compile my own. Debian puts the files in /etc/bind now, not the former place, /var/named thanks -- Andrew On 30-Dec-1999 aphro wrote: > echo -n "Updating permissions for the BIND server ..." > chown named.named /var/named > chown named.named /usr/loc

Re: BIND security question

1999-12-30 Thread aphro
its not hard to do, but you gotta make sure that permissiosn are right on the files all the time..which can be a pain sometimes, if even 1 zone file can't be read bind will puke. on my servers i made a little script to do it for me..: echo -n "Updating permissions for the BIND server ..." chown n

Re: BIND security question

1999-12-30 Thread Pollywog
On 30-Dec-1999 Onno wrote: > At 04:16 PM 12/28/99 -, Pollywog wrote: >> >>On 28-Dec-1999 root wrote: >> >>Was this someone trying to find out which BIND I am running? >>> >>> Unusual System Events >>> =-=-=-=-=-=-=-=-=-=-= >>> Dec 28 06:39:09 lilypad named[342]: unapproved query from >>> [206

Re: BIND security question

1999-12-30 Thread Onno
At 04:16 PM 12/28/99 -, Pollywog wrote: > >On 28-Dec-1999 root wrote: > >Was this someone trying to find out which BIND I am running? >> >> Unusual System Events >> =-=-=-=-=-=-=-=-=-=-= >> Dec 28 06:39:09 lilypad named[342]: unapproved query from [206.79.22.9].1978 >> for "version.bind" >> De

BIND security question

1999-12-28 Thread Pollywog
On 28-Dec-1999 root wrote: Was this someone trying to find out which BIND I am running? > > Unusual System Events > =-=-=-=-=-=-=-=-=-=-= > Dec 28 06:39:09 lilypad named[342]: unapproved query from [206.79.22.9].1978 > for "version.bind" > Dec 28 06:39:09 lilypad named[342]: unapproved query fro