Firewall Wizards mailing list archives
Re: DNS on the Firewall - security problem
From: Darren Reed <avalon () coombs anu edu au>
Date: Sun, 12 Oct 1997 17:29:56 +1000 (EST)
In some mail from Adam Shostack, sie said: [...]
I'm working on a paper on the topic of DNS, and working on some kernel hacks to allow a special user or group (other than root) to bind to low numbered ports. Another way to deal with the problem is to use a packet filter that does port translation so that the DNS server can live on a high numbered port (eg, 5353), and still appear to be on port 53. Both these allow you to run the DNS server as an unprivleged user in a chroot jail. Sorry, the kernel kludges are not available.
You might want to have a look around for implementations already available which do this. I'm pretty sure this has been done by a few people already, once for Linux and one for FreeBSD. Of course neither solution is what I'd call elegant (at this stage) but nor is there anything (that I know of) resembling a POSIX standard which defines how it should be done. Darren
Current thread:
- Re: DNS on the Firewall - security problem Adam Shostack (Oct 10)
- Re: DNS on the Firewall - security problem Alfred Huger (Oct 10)
- Re: DNS on the Firewall - security problem Adam Shostack (Oct 12)
- Re: DNS on the Firewall - security problem Darren Reed (Oct 12)
- Re: DNS on the Firewall - security problem Perry E. Metzger (Oct 12)
- Re: DNS on the Firewall - security problem Aleph One (Oct 12)
- Re: DNS on the Firewall - security problem Gaddy Gumbao (Oct 13)
- Message not available
- Re: DNS on the Firewall - security problem Bernd Eckenfels (Oct 19)
- Re: DNS on the Firewall - security problem Adam Shostack (Oct 12)
- Re: DNS on the Firewall - security problem Alfred Huger (Oct 10)
