Making DNS request to the Internet

Making DNS request to the Internet

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Making DNS request to the Internet boomboom999 05-19-2006
Posted by on May 19, 2006, 10:36 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

Is it considered a good security practice to not allow Active Directory
Domain Controlles making direct DNS requests to the Internet?

I have read about different DNS responses attacks that can help an
attacker to take control of the DC via an incorrect DNS response
(buffer overflow etc.).

Would it be more secure to use DNS forwarders?
If yes, where we should place them? Into DMZ?

Thank you


Posted by Leythos on May 19, 2006, 10:54 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
boomboom999@yahoo.com says...
> Hi,
>
> Is it considered a good security practice to not allow Active Directory
> Domain Controlles making direct DNS requests to the Internet?
>
> I have read about different DNS responses attacks that can help an
> attacker to take control of the DC via an incorrect DNS response
> (buffer overflow etc.).
>
> Would it be more secure to use DNS forwarders?
> If yes, where we should place them? Into DMZ?

If you've got the capital to setup a dedicated DNS server to do the
work, more power to you.

I've never had a customer compromised with a DC also providing DNS
forwarding through a real firewall. We don't allow them to provide
PUBLIC DNS, only DNS internally and Forwarding from LAN.

--

spam999free@rrohio.com
remove 999 in order to email me

Posted by on May 19, 2006, 11:10 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
What could you say about the vulnerabilities mentioned below?

Domain Name System (DNS) stub resolver libraries vulnerable to buffer
overflows via network name or address lookups

http://www.kb.cert.org/vuls/id/844360


Posted by Barry Margolin on May 19, 2006, 11:19 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> boomboom999@yahoo.com says...
> > Hi,
> >
> > Is it considered a good security practice to not allow Active Directory
> > Domain Controlles making direct DNS requests to the Internet?
> >
> > I have read about different DNS responses attacks that can help an
> > attacker to take control of the DC via an incorrect DNS response
> > (buffer overflow etc.).
> >
> > Would it be more secure to use DNS forwarders?
> > If yes, where we should place them? Into DMZ?
>
> If you've got the capital to setup a dedicated DNS server to do the
> work, more power to you.

Even if you don't, you can always forward to your ISP's caching servers.

--
Barry Margolin, barmar@alum.mit.edu
Arlington, MA
*** PLEASE post questions in newsgroups, not directly to me ***
*** PLEASE don't copy me on replies, I'll read them in the group ***

Similar ThreadsPosted
Making an untraceable CD? June 13, 2004, 10:33 am
In the spirit of making compliance a little bit easier October 23, 2008, 7:59 pm
Request. Newsgroup FAQ. TIA March 11, 2005, 3:51 am
CBCP information request December 21, 2004, 9:25 pm
Request for input from someone who has hired or managed an ex-hacker January 25, 2005, 5:39 pm
Request for comments - anti-phishing approach May 29, 2005, 9:55 am
Info request - Penetration Testing tools list May 19, 2005, 8:47 pm
ICMP Type 8 Echo Request packet security concerns October 11, 2005, 5:39 am
Request for help with a hacker project, or simple question answer sought August 5, 2006, 10:00 am
How to Report - Online Frauds, Internet Scams and Phising Emails: -"Web and Internet" - Support & Network Group March 21, 2006, 7:03 pm

The site map in XML format XML site map

Contact Us | Privacy Policy