[rescue] Tricking DNS

Kevin Loch rescue at sunhelp.org
Mon Oct 22 10:25:13 CDT 2001


"Loomis, Rip" wrote:
> *Don't* use the BIND that's included with Solaris, whatever
> you do, unless you have someone holding a gun to your head.
> Historically, it has taken Sun anywhere from 4 to 24 weeks
> to get patches out for "their" BIND implementations--and that's
> an unacceptable window of vulnerability.  As with Sendmail,
> if you need the functionality then use the latest stable
> and secure release, rather than sticking with the Sun version.

That is exactly what I meant.  FWIW, don't use Solaris Sendmail,
FTP,  or any publicly accessible service.  It is good engineering
practice to compile external services yourself from latest good 
source code (not counting beta/pre-release of course).

KL



More information about the rescue mailing list