Bug 929336 - bind recursive open-servers are evil. Add warning to named.conf
Summary: bind recursive open-servers are evil. Add warning to named.conf
Keywords:
Status: CLOSED DUPLICATE of bug 740894
Alias: None
Product: Fedora
Classification: Fedora
Component: bind
Version: rawhide
Hardware: All
OS: All
unspecified
medium
Target Milestone: ---
Assignee: Tomáš Hozza
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-03-29 18:01 UTC by Wolfgang Rupprecht
Modified: 2013-05-03 09:41 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-05-03 09:41:30 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Wolfgang Rupprecht 2013-03-29 18:01:27 UTC
Description of problem:

Open recursive dns servers are the new scourge of the internet.  They are used by botnets to send multi-gigabyte DDOS streams to a third-party victim site.  

https://www.isc.org/wordpress/is-your-open-dns-resolver-part-of-a-criminal-conspiracy/

The delivered /etc/named.conf file really needs a short note to any newbie admin that they need to take great care to not open up their resolver to the world at large.   As it is, all the old-timers know that you aren't supposed to do this, but where is a newbie supposed to find this out?  

There are mutterings that some Red Hat products (RHEL) might even be delivered with an open resolver as default.  Please propagate this bug to the other products if appropriate.

Medium severity was chosen only because this is a serious bug that is actively being exploited in the wild, but it does have a config-file runtime work around.

Version-Release number of selected component (if applicable):


How reproducible:


Steps to Reproduce:
1.
2.
3.
  
Actual results:


Expected results:


Additional info:

Comment 1 Fedora Admin XMLRPC Client 2013-04-25 11:37:50 UTC
This package has changed ownership in the Fedora Package Database.  Reassigning to the new owner of this component.

Comment 2 Tomáš Hozza 2013-05-03 09:41:30 UTC

*** This bug has been marked as a duplicate of bug 740894 ***


Note You need to log in before you can comment on or make changes to this bug.