Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 08-09-2008, 10:14 AM   #1
buyandsell
Confirmed User
 
Industry Role:
Join Date: May 2008
Location: USA
Posts: 692
hey I hope you all upgraded your DNS

http://www.isc.org/index.pl?/sw/bind/bind-security.php
buyandsell is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-09-2008, 10:19 AM   #2
mrwilson
mrwilson 2.0
 
Industry Role:
Join Date: Jul 2007
Location: ICQ: 465406783
Posts: 5,122
Thanks for the heads up
mrwilson is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-10-2008, 06:59 AM   #3
nico-t
emperor of my world
 
Join Date: Aug 2004
Location: nethalands
Posts: 29,903
i dont understand, what is this.. too technical to even bother to read it
nico-t is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-10-2008, 07:24 AM   #4
TheDoc
Too lazy to set a custom title
 
TheDoc's Avatar
 
Industry Role:
Join Date: Jul 2001
Location: Currently Incognito
Posts: 13,827
Quote:
Originally Posted by nico-t View Post
i dont understand, what is this.. too technical to even bother to read it
You can read the Wired down version of what's going on here.
__________________
~TheDoc - ICQ7765825
It's all disambiguation
TheDoc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-10-2008, 12:23 PM   #5
fluffygrrl
So Fucking Banned
 
Join Date: May 2006
Posts: 2,187
O brother.

This is a rare day indeed.
fluffygrrl is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-10-2008, 01:08 PM   #6
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
thanks for the update spanno
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-10-2008, 03:00 PM   #7
Adult Creative Labs
Confirmed User
 
Adult Creative Labs's Avatar
 
Join Date: Jul 2008
Location: Global
Posts: 221
I've been reading about this for a month now. It is truly worrying.
__________________
.



ICQ: 498299527
Email: sales -at- adultcreativelabs.com

Adult Creative Labs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-10-2008, 03:08 PM   #8
qxm
Confirmed User
 
Join Date: Jul 2006
Location: NoHo
Posts: 5,970
It would be nice to hear about security measures being taken from major hosting companies about this !!!

Come on WEBAIR, MOJO, PHAT, ISPRIME, PR and all other I forgot to mention !!!....
__________________

ICQ: 266990876
qxm is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-10-2008, 04:49 PM   #9
jollyperv
Confirmed User
 
Industry Role:
Join Date: Nov 2001
Location: NYC
Posts: 3,927
Quote:
Originally Posted by qxm View Post
It would be nice to hear about security measures being taken from major hosting companies about this !!!

Come on WEBAIR, MOJO, PHAT, ISPRIME, PR and all other I forgot to mention !!!....
Yep, would be nice to hear
jollyperv is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-10-2008, 05:13 PM   #10
Manowar
jellyfish  
 
Join Date: Dec 2003
Posts: 71,528
sounds pretty fucked
Manowar is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-10-2008, 05:18 PM   #11
Iron Fist
Too lazy to set a custom title
 
Join Date: Dec 2006
Posts: 23,400
The world fall apart yet? No?? Okay then.... keep moving folks...
__________________
i like waffles
Iron Fist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-10-2008, 06:19 PM   #12
GrouchyAdmin
Now choke yourself!
 
GrouchyAdmin's Avatar
 
Industry Role:
Join Date: Apr 2006
Posts: 12,085
Bind security holes? What's next? a problem with sendmail!?
__________________
GrouchyAdmin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-10-2008, 08:05 PM   #13
Evil E
Confirmed User
 
Join Date: Apr 2005
Location: Lazyness is a lifestyle
Posts: 3,201
Quote:
Originally Posted by GrouchyAdmin View Post
Bind security holes? What's next? a problem with sendmail!?
LOL that made me laugh, but this doesn't have to do with BIND but with the way DNS was designed as the others name daemons are also vulnerable.
__________________


A girl once told me "Give me 8 inches and make it HURT".

So, I fucked her twice and hit her with a brick.
Evil E is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-10-2008, 08:06 PM   #14
Evil E
Confirmed User
 
Join Date: Apr 2005
Location: Lazyness is a lifestyle
Posts: 3,201
Quote:
Originally Posted by qxm View Post
It would be nice to hear about security measures being taken from major hosting companies about this !!!

Come on WEBAIR, MOJO, PHAT, ISPRIME, PR and all other I forgot to mention !!!....
Patches have been out for about a month. If it wasn't patched then your hosting co probably knows less than you about anything.
__________________


A girl once told me "Give me 8 inches and make it HURT".

So, I fucked her twice and hit her with a brick.
Evil E is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-10-2008, 08:47 PM   #15
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
Quote:
Originally Posted by sharphead View Post
The world fall apart yet? No?? Okay then.... keep moving folks...
you would wait for the world to fall apart before fixing it ?
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-10-2008, 08:57 PM   #16
Iron Fist
Too lazy to set a custom title
 
Join Date: Dec 2006
Posts: 23,400
Quote:
Originally Posted by SmokeyTheBear View Post
you would wait for the world to fall apart before fixing it ?
__________________
i like waffles
Iron Fist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-10-2008, 11:14 PM   #17
ne0
Confirmed User
 
Join Date: May 2006
Location: brazil
Posts: 781
Hello,
As I see some of our clients sent us questions about this issue, guided by this particular thread.
Just want you to know that we actually have this covered for a while.
This vulnerability is not new and is the reply to many of those interesting '302 errors' webmasters experiences sometimes.
While dnssec is the reply for this problem this isn't something widely spread.
What most sysadmins are doing right now, is raise the range of ports used to reply the queries making the guessing harder.
This happens for a while and exploits for this have been running the internet for about two years or so.
__________________
hai2u
ne0 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-10-2008, 11:41 PM   #18
spooky181
Confirmed User
 
Join Date: Jul 2003
Location: back of beyond
Posts: 2,951
Quote:
Originally Posted by SplitNeo View Post
Hello,
As I see some of our clients sent us questions about this issue, guided by this particular thread.
Just want you to know that we actually have this covered for a while.
This vulnerability is not new and is the reply to many of those interesting '302 errors' webmasters experiences sometimes.
While dnssec is the reply for this problem this isn't something widely spread.
What most sysadmins are doing right now, is raise the range of ports used to reply the queries making the guessing harder.
This happens for a while and exploits for this have been running the internet for about two years or so.
Thanks, one of the many reasons I am with you guys....
spooky181 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-11-2008, 12:09 AM   #19
rhcp011235
Confirmed User
 
rhcp011235's Avatar
 
Industry Role:
Join Date: Sep 2007
Location: North Carolina
Posts: 538
ISPRIME doesnt use bind. Thus no security issues

NEXT!
__________________
Skype rhcp011235 | Cell Phone 212.812.9043 | Email [email protected]
rhcp011235 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-11-2008, 12:22 AM   #20
ne0
Confirmed User
 
Join Date: May 2006
Location: brazil
Posts: 781
Just that it's not only bind
Any caching server that is open to recursive queries is vulnerable.
But I'm pretty sure isprime got that covered as well
__________________
hai2u
ne0 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-11-2008, 04:20 AM   #21
DutchTeenCash
I like Dutch Girls
 
DutchTeenCash's Avatar
 
Join Date: Feb 2003
Location: dutchteencash.com
Posts: 21,684
thanks good read
DutchTeenCash is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-11-2008, 04:30 AM   #22
born4porn
FUKM ALL!
 
born4porn's Avatar
 
Join Date: Jan 2004
Location: somewhere wet n sticky - Sydney
Posts: 38,781
thanks 4 the heads up!!
born4porn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-11-2008, 07:33 AM   #23
WebairGerard
Confirmed User
 
Industry Role:
Join Date: Sep 2005
Posts: 8,113
We have been aware of this vulnerability as it is not new.
Webair does not use bind and this does not impact any of our clients or services.
__________________

WebairGerard is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-11-2008, 03:08 PM   #24
split_joel
Confirmed User
 
Join Date: Jan 2005
Posts: 2,270
It doesn't just affect bind.
__________________
E-mail marketing - Automation Scripting - IP Space
AIM: splitjoelp ICQ: 254759453 skype - splitjoelp 702-941-6465
split_joel is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-11-2008, 04:26 PM   #25
Los
Confirmed User
 
Join Date: Jul 2001
Location: San Francisco
Posts: 427
lol this isnt a bug in bind this is a bug in the design of dns just about every maker has been effected.
Los is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-11-2008, 04:51 PM   #26
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
dns posining isnt a bind thing, every dns daemon has some vuln to it
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.