[plug] OT: latest worm affecting bind

Mike Holland myk at golden.wattle.id.au
Thu Mar 29 09:57:50 WST 2001


I have the UDP dns port open for receiving replies, as in the HOWTO.

    # Accept DNS answers on privileged port.
    ipchains -A input -j ACCEPT -i ppp+ -d 0/0 53 -p udp

Is that safe? I closed it and bind still seems to work locally, presumably
getting replies back over a TCP connection that my end opened.

Why might I want the UDP port open, as given in the HOWTO example?

-- 
Mike Holland  <mike at golden.wattle.id.au>
                          --==--
    I had no shoes and I pitied myself.  Then I met a man who had no
    feet, so I took his shoes.            -- Dave Barry




More information about the plug mailing list