Scanning Alexa's Top 1M for AXFR
en.internetwache.org
en.internetwache.org
In BIND, this is configured by the allow-transfer option. You can explicitly allow your slaves with an option like:
allow-transfer { 192.168.1.1; };
Or, disable all transfers by specifying "none;". This can be done on a per-zone basis, as well, though the global section will apply in the absence of zone-specific configuration, which I suspect is how so many servers are misconfigured (i.e. there is no rule in place to block it in the global section, so it is allowing all for zones that don't have an allow-transfer section). I just noticed that some of my zones on slave servers fall prey to this, as well, even though I know better. The default seems to be to allow all, if allow-query allows all.That said, I'm not overly alarmed. Very little (roughly zero) sensitive data exists in my world-facing zones.
We thought about putting some "example fixes/configurations" into the blogpost, but then abandoned the idea, because there are a lot of different DNS servers out there.
Only covering a few didn't seem useful to us.
So thank you for giving an example configuration for BIND :)
Thanks!
http://www.cyberciti.biz/faq/linux-unix-bind9-named-configur...
that's another good point!
Thanks for bringing it up.