Firewall Wizards mailing list archives

Re: DNS on the Firewall - security problem


From: Darren Reed <avalon () coombs anu edu au>
Date: Sun, 12 Oct 1997 17:29:56 +1000 (EST)

In some mail from Adam Shostack, sie said:
[...]
I'm working on a paper on the topic of DNS, and working on some kernel
hacks to allow a special user or group (other than root) to bind to
low numbered ports.  Another way to deal with the problem is to use a
packet filter that does port translation so that the DNS server can
live on a high numbered port (eg, 5353), and still appear to be on
port 53.  Both these allow you to run the DNS server as an unprivleged
user in a chroot jail.

Sorry, the kernel kludges are not available.

You might want to have a look around for implementations already available
which do this.  I'm pretty sure this has been done by a few people already,
once for Linux and one for FreeBSD.  Of course neither solution is what I'd
call elegant (at this stage) but nor is there anything (that I know of)
resembling a POSIX standard which defines how it should be done.

Darren



Current thread: