Great Circle Associates Firewalls
(November 1993)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: IDENT secure?
From: Piete . Brooks @ cl . cam . ac . uk
Date: Wed, 17 Nov 93 07:57:33 +0000
To: pmetzger @ lehman . com
Cc: alastair @ cadence . com (Alastair Young), firewalls @ GreatCircle . COM, Piete . Brooks @ cl . cam . ac . uk
In-reply-to: Your message of Tue, 16 Nov 93 11:02:17 -0500. <9311161602 . AA16861 @ snark . lehman . com>

> problems will go away. DO NOT link anything from the bind distribution
> in to your normal sun software -- in particular, producing a new
> shared libc from the bind sources is BAD BAD BAD. This is because the
> braindamaged sun versions of the berkeley "r"commands expect
> libresolv.a to do some of their security checks for them! Really
> stupid, but it means that you have to use the broken sun libresolv for
> anything else.

Well, as nobody else has leapt to BIND's defence I feel I had better so do.

I have been using BIND generated shared libc's on my suns for years.
They do double reverse lookups. The OPTIONS file says:

	SUNSECURITY (origin: rossc @
 ucc .
 su .
 oz .
 au)
	        enable checking of PTR records in gethostbyaddr() to detect
	        spoofing. Always on on suns as rlogin etc. depend on this.

Are you saying that there is some other problem of which I am not aware ?


Follow-Ups:
References:
Indexed By Date Previous: Re: ident servers -- uname or uid?
From: Darren Reed <avalon @ coombs . anu . edu . au>
Next: socksified version of NCSA telnet for macs ???
From: ianh @ resmel . bhp . com . au (Ian Hoyle)
Indexed By Thread Previous: Re: IDENT secure?
From: "Perry E. Metzger" <pmetzger @ lehman . com>
Next: Re: IDENT secure?
From: "Perry E. Metzger" <pmetzger @ lehman . com>

Google
 
Search Internet Search www.greatcircle.com