> First and foremost, you need to upgrade your version of BIND.  It is
> vulnerable to the recent DNS cache poisoning vulnerability that I'm sure
> you have heard about by now..

> OK, so I'm not running *real* BIND, but Redhat's "special" version 
> (bind-9.2.4-22.el3).

That bind-9.2.4-22.el3 appears to be Red Hat's fixed version:

