[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: xinetd /etc/host.deny ALL:PARANOID



also sprach Nathan E Norman <nnorman@micromuse.com> [2002.01.11.0501 +0100]:
> Congratulations ... you just set up your DNS incorrectly.  Every PTR
> entry should resolve to a _unique_ name, and that name should resolve
> to a _unique_ IP.  That doesn't mean you can't have additional A
> records doing load balancing. 

good point. i never used DNS RR, so sorry. there are better ways. i
should have thought more.

> zone IN 3.2.1.in-addr.ARPA:
> 
>   4 IN PTR host4.netblk1-2-3.madduck.net.
>   4 IN PTR host5.netblk1-2-3.madduck.net.
    ^
    5

just for clarification.

> Not all A records need PTR records.  It never fails to amaze me how
> many people don't understand this.

exactly my point. which is why i disabled PARANOID and still don't get
hacked.

> Having said that, I know there are plenty of retarded netblock owners
> out there.

i do have to speak for one actually, because i am amazed.

   speakeasy.net

we had three IPs, we wanted another -> 4 hours

this is a private DSL subscription,
but we wanted custom reverse IP     -> 3 hours

seriously: wow!

-- 
martin;              (greetings from the heart of the sun.)
  \____ echo mailto: !#^."<*>"|tr "<*> mailto:"; net@madduck
  
in africa some of the native tribes have a custom of beating the
ground with clubs and uttering spine chilling cries. anthropologists
call this a form of primitive self-expression. in america they call
it golf.

Attachment: pgpEe3ulhq3wV.pgp
Description: PGP signature


Reply to: