Bug#732610: dnsmasq: listen only to loopback device by default

2013-12-19 Thread Michael Prokop
Package: dnsmasq Version: 2.68-1 Severity: normal I've been involved in two situations already where a default dnsmasq installation was misused for DDoS nameserver attacks, because dnsmasq is listening on all network devices without any real limitations by default. Something like: % cat

Bug#732610: dnsmasq: listen only to loopback device by default

2013-12-19 Thread Simon Kelley
On 19/12/13 10:51, Michael Prokop wrote: Package: dnsmasq Version: 2.68-1 Severity: normal I've been involved in two situations already where a default dnsmasq installation was misused for DDoS nameserver attacks, because dnsmasq is listening on all network devices without any real limitations

Bug#732610: dnsmasq: listen only to loopback device by default

2013-12-19 Thread Michael Prokop
* Simon Kelley [Thu Dec 19, 2013 at 04:10:10PM +]: On 19/12/13 10:51, Michael Prokop wrote: I've been involved in two situations already where a default dnsmasq installation was misused for DDoS nameserver attacks, because dnsmasq is listening on all network devices without any real