tech-security archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: NetBSD Security Advisory 2011-005: ISC dhclient hostname field shell metacharacter injection



    Date:        Thu, 28 Apr 2011 13:33:52 +0930
    From:        Brett Lymn <blymn%baea.com.au@localhost>
    Message-ID:  <20110428040351.GH12989%baea.com.au@localhost>

  | Someone needs to tell ISC then - BIND has been, by default, rejecting
  | names with _ in them for years.

I know, and they know, and they ignore it...   I used to remove that
code from bind, these days I just configure it away.

kre



Home | Main Index | Thread Index | Old Index