OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Russell Fulton (r.fultonAUCKLAND.AC.NZ)
Date: Wed Jan 31 2001 - 15:41:44 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Wed, 31 Jan 2001 10:47:24 -0800 "Somaini, Justin"
    <Justin.SomainiSCHWAB.COM> wrote:

    > Has anyone seen attacks, other than Microsoft, in regards to the bind tsig
    > vuln.?

    I've seen an increase in version probes against our advertised name
    servers.

    One question: I understand that the tsig vulnerability is in the
    DNSSEC code and, so far as I am aware, we are not using this now. Are
    there any options in the BIND config to disable DNSSEC? (as a stop gap
    until we can get the software upgraded).

    Russell Fulton, Computer and Network Security Officer
    The University of Auckland, New Zealand