> Get a good monitoring system like Mon
> ( that will check that your serials
> match. That way you don't have to roll your own.

although the weird thing in this case is that the serials did match; i
think that one of the machines just had incorrect cache information.

my guess is that a newer version of bind would be less succeptible to
this sort of poisoning, no?

jazz% dig version.bind ch txt +sh
in any event unless this is a vendor patched version of bind that's
completely patched of the various security holes in that version (and in
fact even if it is), i'd highly recommend upgrading.

you might also consider restricting axfr from outside your network.


