More on the DNS/BIND Problems...and one solution...

sinck@ugive.com sinck@ugive.com
Tue, 30 Jan 2001 21:15:44 -0700


\_ Anyone out there have any other good BIND or other Security 
\_ solution stories to share?
 
Besides the obvious reasons to subscribe to Bugtraq, you occasionally
run across gems like (paraphrasing)

  From: microsoft-security
  Subject: another .HTR vulnerability

  ... In addition to the previous two .htr access vulnerabilities,
  there is another that can be checked by ....

You'd like to think after *two* previous vulnerabilities, that they
would have peered at the code hard enough to root out others.

OMG, maybe they did.  Eeeek.

David