Free Republic
Browse · Search
General/Chat
Topics · Post Article

More difficulties for the 'doze Server...
1 posted on 12/08/2015 10:19:18 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies ]


To: dayglored

Ping!


2 posted on 12/08/2015 10:19:48 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer

I have to speak to this at a management meeting this morning. Here are some of the finer points:

1. This is targeted at Internet-facing DNS servers. The likelihood of an external attack against a NATted private network is very small.

2. Server 2012 Active Directory domain controllers require the installation of DNS during promotion, making DCs particularly vulnerable.

3. If you’re running external resolvers on DCs, shame on you.

4. While Microsoft states there are no mitigating controls, blocking TCP 53 on edge firewalls prevents DNS lookups from getting to your servers.

and... again...

5. See #3

This is, again, much ado about nothing if you’re an enterprise-minded system administrator. I’ve never worked for a company that used Windows for edge DNS resolution. That’s usually handled at the ISP or by GTMs in the DMZ.


5 posted on 12/09/2015 4:24:37 AM PST by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer

How several thousand self-congratulating and thoroughly egotistical software engineers can accidentally build a back door into everything they write is bewildering.


7 posted on 12/09/2015 6:49:36 AM PST by GingisK
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson