secure NAMED

8 September 2008 | 0 تعليقات

Stop Recursion DNS :-

A DNS query may be either a recursive query or a non-recursive query. If recursion is set to ‘yes’ (the default) the server will always provide recursive query behaviour if requested by the client (resolver). If set to ‘no’ the server will only provide iterative query behaviour. If the answer to the query already exists in the cache it will be returned irrespective of the value of this statement. This statement essentially controls caching behaviour in the server.

Open named.conf file and make sure following settings exists under Options { … } settings:
recursion no;
Save and close the file. Reload named
# service named restart

Hide BIND DNS Sever Version:-

Open your named.conf file, find out options { … }; section,
options
{
query-source port 53;
query-source-v6 port 53;
listen-on { 174.ttt.xx.yy; };
directory "/var/named"; // the default
dump-file "data/cache_dump.db";
statistics-file "data/named_stats.txt";
memstatistics-file "data/named_mem_stats.txt";
dnssec-enable yes;
recursion no;
allow-notify { 174.zzz.yy.zz; 172.xx.yy.zz; };
version "BIND";
};

To hide your bind version:
version "YOUR Message";
Save and close the file. Restart named, enter:
# service named restart

u can see ur named server virsion by using
$ dig @ns1.softlayer.com -c CH -t txt version.bind

التعليقات

أضف تعليقا

الاسم (مطلوب)

البريد الإلكتروني (لن يعرض للآخرين) (مطلوب)

الموقع

أطلق العنان لحروفك