Cache poisoning vulnerability found in BIND
Posted Jul 26, 2007 4:49 UTC (Thu) by
flewellyn (subscriber, #5047)
In reply to:
Cache poisoning vulnerability found in BIND by smoogen
Parent article:
Cache poisoning vulnerability found in BIND
No, the only thing that would matter to the firewall is the destination port, which, since DNS is a
Well Known Service, is always the same. The source port for the querying machine could be
anything; unless the firewall is configured to block outgoing ports, which is just silly, the DNS
server can respond on any port. If the port in question is randomized for each query, it makes
no difference.
(
Log in to post comments)