Re: Update to BIND query.c CVE-2011-4313

2011-12-05 Thread Chris Thompson
On Dec 5 2011, Susan Graves wrote on bind-announce: Dear BIND-Users, Please see today's update to CVE-2011-4313 (https://www.isc.org/software/bind/advisories/cve-2011-4313) regarding ISC's final analysis of this event. Also, please review our KnowledgeBase article (_https://deepthought.isc.or

dig nssearch minor mystery

2011-12-05 Thread M. Meadows
Just wondering why dig with nssearch and "@" produced two different answers when I ran it today. I assume the @8.8.8.8 (in the example below) isn't actually happening ... or it happened in one test and not the other. The results below were exactly as I saw them in the order that they are lis

Re: Botnet Malware issue on bind BIND 9.7.1-P2

2011-12-05 Thread WBrown
jagan padhi wrote on 12/05/2011 12:16:19 PM: > First of all i would like to know what all these .ws domians.due to > this junk domain query CDNS servers load are getting very high. > > Yes There is a limit set in my CDND server,however out of 100 query > 60 queries are coming for these junk

Re: Botnet Malware issue on bind BIND 9.7.1-P2

2011-12-05 Thread jagan padhi
Yes Michael, First of all i would like to know what all these .*ws* domians.due to this junk domain query CDNS servers load are getting very high. Yes There is a limit set in my CDND server,however out of 100 query 60 queries are coming for these junk domains. I am running with BIND 9.7.1-P2 an

Re: nanny (was Re: bind-9.8.1: INSIST(! dns_rdataset_isassociated(sigrdataset)) failed)

2011-12-05 Thread Michael Graff
On Nov 18, 2011, at 4:44 AM, G.W. Haywood wrote: > Never in several machine decades have I had to do anything like that > for BIND. The fact that people are even talking about it is of some > concern to me. Twice in approximately the last month I have had one > particular server go down for no

Re: Botnet Malware issue on bind BIND 9.7.1-P2

2011-12-05 Thread Michael Graff
I see many valid IP addresses in your list. But that said, are the responses going back "large" individually, or is it the number of them that is "large"? If you think this is attempting to crash the server with a single large answer, that's different than if your server is getting a lot of que

Re: Botnet Malware issue on bind BIND 9.7.1-P2

2011-12-05 Thread jagan padhi
> > Hi, > > There are huge request are coming frm the valid ip with .ws domain which > are not exist and causes degrade the server performance. > > > Thanks, > Jagan > > www3.cbox.ws.barnasinternational.com. (65) > 14:24:41.223958 IP 211.164.230.208.17125 > 103.145.184.40.domain: 64+ A? > mlv

Botnet Malware issue on bind BIND 9.7.1-P2

2011-12-05 Thread jagan padhi
Hi, Pls suggest on this. Thanks, Jagan www3.cbox.ws.barnasinternational.com. (65) 14:24:41.223958 IP 211.164.230.208.17125 > 103.145.184.40.domain: 64+ A? mlvabdz.ws. (28) 14:24:41.300652 IP 61.246.253.55.44111 > 208.73.210.76.domain: 47143 [1au] A? xoguzsdl.ws. (40) 14:24:41.338215 IP 211.1

Re: Zone Transfer Query

2011-12-05 Thread Phil Mayers
On 05/12/11 12:43, Gaurav Kansal wrote: I have already check this too. I have done an entry in "allow-transfer" ACL. Show the relevant config - the zone & ACL from the master, and the zone statement from the slave. Are you sure the allow-transfer ACL includes the correct IP family i.e. if y

RE: Zone Transfer Query

2011-12-05 Thread Gaurav Kansal
I have already check this too. I have done an entry in "allow-transfer" ACL. -Original Message- From: bind-users-bounces+gaurav.kansal=nic...@lists.isc.org [mailto:bind-users-bounces+gaurav.kansal=nic...@lists.isc.org] On Behalf Of Phil Mayers Sent: Monday, 05 December, 2011 6:07 PM To: b

Re: Zone Transfer Query

2011-12-05 Thread Ben Croswell
I would imagine the IP you trying to transfer on is not in the allow-query acl of the master. You have to be to do soa queries to the master. -Ben Croswell On Dec 5, 2011 7:34 AM, "Gaurav Kansal" wrote: > Dear All, > > ** ** > > I have a master DNS on IPv4 AND slave DNS on IPv6. > > I al

Re: Zone Transfer Query

2011-12-05 Thread Phil Mayers
On 05/12/11 12:32, Gaurav Kansal wrote: Dear All, I have a master DNS on IPv4 AND slave DNS on IPv6. I also have a IPv4 address on slave (But only IPv6 address is entered in NS). Now I am trying to transfer my zone from master to slave through the IPv4 address. But it is giving me a error “fai

Zone Transfer Query

2011-12-05 Thread Gaurav Kansal
Dear All, I have a master DNS on IPv4 AND slave DNS on IPv6. I also have a IPv4 address on slave (But only IPv6 address is entered in NS). Now I am trying to transfer my zone from master to slave through the IPv4 address. But it is giving me a error "failed while receiving responses: REFUS