BIND workaround for older versions?

View: New views
7 Messages — Rating Filter:   Alert me  

BIND workaround for older versions?

by Mike Shaw-2 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Regarding the cache poisoning patch (which I see for 4.3).  Are there
any effective workarounds for OpenBSD 4.0/4.1?

I have a couple older boxes I will be upgrading, but I'd like to CMA
in the meantime.

Thanks!
-Mike


Re: BIND workaround for older versions?

by Aaron Stellman :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

On Thu, Jul 24, 2008 at 02:48:45PM -0500, Mike Shaw wrote:
> Regarding the cache poisoning patch (which I see for 4.3).  Are there
> any effective workarounds for OpenBSD 4.0/4.1?
>
> I have a couple older boxes I will be upgrading, but I'd like to CMA
> in the meantime.
>
> Thanks!
> -Mike
>
Perhaps you'd want to look at pf workaround to this. look at misc@
archives from 2008-07-19.


Re: BIND workaround for older versions?

by Stuart Henderson :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

On 2008-07-24, Mike Shaw <shawnuff@...> wrote:
> Regarding the cache poisoning patch (which I see for 4.3).  Are there
> any effective workarounds for OpenBSD 4.0/4.1?

The 4.2 patch should also work for 4.1


Re: BIND workaround for older versions?

by Mike Shaw-2 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Ah...perfect.  Thanks Stuart and Aaron.

-Mike


On Thu, Jul 24, 2008 at 2:57 PM, Aaron Stellman <openbsd-misc@...> wrote:

> On Thu, Jul 24, 2008 at 02:48:45PM -0500, Mike Shaw wrote:
>> Regarding the cache poisoning patch (which I see for 4.3).  Are there
>> any effective workarounds for OpenBSD 4.0/4.1?
>>
>> I have a couple older boxes I will be upgrading, but I'd like to CMA
>> in the meantime.
>>
>> Thanks!
>> -Mike
>>
> Perhaps you'd want to look at pf workaround to this. look at misc@
> archives from 2008-07-19.


Re: BIND workaround for older versions?

by Guido Tschakert :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Stuart Henderson schrieb:
> On 2008-07-24, Mike Shaw <shawnuff@...> wrote:
>> Regarding the cache poisoning patch (which I see for 4.3).  Are there
>> any effective workarounds for OpenBSD 4.0/4.1?
>
> The 4.2 patch should also work for 4.1
>
>
I can confirm that the 4.2 patch works with 4.1 (at least for me).


guido


Re: : BIND workaround for older versions?

by Raimo Niskanen-7 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

On Fri, Jul 25, 2008 at 07:36:43AM +0200, Guido Tschakert wrote:
> Stuart Henderson schrieb:
> > On 2008-07-24, Mike Shaw <shawnuff@...> wrote:
> >> Regarding the cache poisoning patch (which I see for 4.3).  Are there
> >> any effective workarounds for OpenBSD 4.0/4.1?
> >
> > The 4.2 patch should also work for 4.1
> >
> >
> I can confirm that the 4.2 patch works with 4.1 (at least for me).

+1

>
>
> guido

--

/ Raimo Niskanen, Erlang/OTP, Ericsson AB


Re: BIND workaround for older versions?

by Nick Holland :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Raimo Niskanen wrote:

> On Fri, Jul 25, 2008 at 07:36:43AM +0200, Guido Tschakert wrote:
>> Stuart Henderson schrieb:
>> > On 2008-07-24, Mike Shaw <shawnuff@...> wrote:
>> >> Regarding the cache poisoning patch (which I see for 4.3).  Are there
>> >> any effective workarounds for OpenBSD 4.0/4.1?
>> >
>> > The 4.2 patch should also work for 4.1
>> >
>> >
>> I can confirm that the 4.2 patch works with 4.1 (at least for me).
>
> +1

But...what if it didn't?

This is why you have to keep your systems up-to-date, and the
upgrade plans have to be part of your original implementation.

Years ago, I quit doing data recovery for my clients.  It
became clear that every time I hauled a client's data out of
the proverbial fire, rather than taking it as a lesson about
how important backups are, they took it as a "lesson" that
backups weren't that important, and "Nick can get our data
back", and thus, got more careless rather than more careful.
My calculation was that they would lose less data if I let
them lose a little now (or pay through the nose and a few
other orifices to the big data recovery services) rather
than recover it now and NOT be able to recover it next time.

I fear that people finding out their old systems can be
"salvaged" by back-porting patches are just going to take
this as "Well, upgrades aren't really that important".

Come on...DNS servers running OpenBSD?  That's one of the
easier upgrades you can do...it's all base!  (Unlike some
certain other OS where they bundle stuff in, claim they
support the OS for many years, but things like BIND don't
really count...  *sigh*).

KEEP YOUR BLOOMIN' SYSTEMS UP TO DATE!

Nick.

LightInTheBox - Buy quality products at wholesale price!