Great Circle Associates Firewalls
(July 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: DNS leakage
From: C Matthew Curtin <cmcurtin @ fahlgren . com>
Date: Wed, 10 Jul 1996 22:57:37 -0400
To: Shepherd Rudie <ShepherdR @ Aforbes . co . za>
Cc: "'firewalls @ greatcircle . com'" <firewalls @ GreatCircle . COM>
In-reply-to: <c=ZA%a=_%p=Aforbes%l=AFJHB1EXCH1-960709165142Z-8 @ afjhb1exch1 . aforbes . co . za>
References: <c=ZA%a=_%p=Aforbes%l=AFJHB1EXCH1-960709165142Z-8 @ afjhb1exch1 . aforbes . co . za>
Reply-to: cmcurtin @ fahlgren . com

>>>>> "SR" == Shepherd Rudie <ShepherdR @
 Aforbes .
 co .
 za> writes:

SR> Problem is this: The last time my zone was transferred to my ISP,
SR> the INTERNAL names suddenly appeared on the internet! Of course
SR> this wrecked e-mail and other things as well, but how is this
SR> possible? How can the outside DNS provide the secondary with any
SR> information regarding the inside? BTW the inside network is not
SR> even accessible from the Internet (and thus the secondary
SR> DNS). Any ideas?

You need to figure out which file with your internal stuff is being
sent outside. Make sure that there aren't any major errors like
internal stuff in outside zones, etc., and then once you've located
the files with the inside stuff, take a look at your zone transfer
logs. That will tell you how things got sent out...

The man page on named is your friend.

-- 
C Matthew Curtin                                                Chief Hacker
Fahlgren, Inc.    655 Metro Pl S, Ste 700, Box 7159     Dublin OH 43017-7159
http://www.local.com/~cmcurtin/   cmcurtin @
 fahlgren .
 com   PGP Mail Preferred


References:
  • DNS leakage
    From: Shepherd Rudie <ShepherdR @ Aforbes . co . za>
Indexed By Date Previous: Re: Dirty dogs
From: James Proffer <james @ mail . state . mo . us>
Next: Re: Dirty dogs
From: Don Carney <dcarney @ hypersurf . com>
Indexed By Thread Previous: DNS leakage
From: Shepherd Rudie <ShepherdR @ Aforbes . co . za>
Next: Re: DNS leakage
From: Louis Twomey <twomey @ mog . ucd . ie>

Google
 
Search Internet Search www.greatcircle.com