Re: which dns server to use ?


> Now, maybe I'm just ignorant, but are there any root exploits on Bind9? 
> (specifically 9.x, not anything older.. we know 8.x was unstable =P)

Well, maybe I'm just a bit cynical, but I don't think that any piece of
software can evolve to gain a more inherently secure design. Frankly, no
amount of partial rewrites would make me trust BIND.

Even if it would have been rewritten from scratch, I'd have some trouble
believing that it took them till 2001, but that now, finally, the ISC
understands that you shouldn't trust user input, that you should free
your mallocs, and, most importantly, that you should check if a string
fits before you copy it somewhere.

Some people think C makes these things hard, but I think that you can
only have as trouble as the ISC's been having with it if you have a
fundamentally broken programming style.

All IMHO, of course.



Reply to: