Root Name Servers won't respond to named.

milton at milton at
Tue Mar 27 22:35:19 UTC 2001

In message <p0510081bb6e6bb56c515@[]>, Brad Knowles writes:
> At 10:52 AM -0700 3/27/01, milton at wrote:
> >  I'm reluctant to upgrade beyond what comes from redhat.  I don't 
> >belive that's
> >  what the problem is.  I was previously at 8.2.2 and all of a sudden 
> >it stopped
> >  working.
> 	Problem is, BIND 8.2.2 has a root compromise that means anyone in 
> the world can own your machine in nanoseconds.  There's even a Linux 
> "worm" going around that will automatically compromise any vulnerable 
> machine it encounters.  See 
> <> and 
> <>.  Note that the latter is 
> dated January 29, 2001.
> 	Obviously, you're one of the sites that would be compromised by 
> the Linux Lion Worm (and probably already has been), since you didn't 
> apply the update to your machines when the problem was first 
> published in January.

No, I don't believe so... I'm familiar with the worm as it has affected 
other machines I know about and I have cleaned up afer it.  I did one
clean up by giving instructions over the phone, as I would not login because
hte host did not have ssh.    I don't believe that I'm subject to 
this problem as my named is behind a masquared firewall.  There is no direct 
access from the internet to my named.

> 	I still suggest getting at least 8.2.3-REL and installing it on 
> your machines, if not trying the latest release candidate for 9.1.1 
> (currently at 9.1.1rc7).  Ideally, you'd also download the source 
> code and compile it for yourself, because you can't be sure that the 
> binary RPMs you download have not themselves been trojaned.
