Thread: Open DNS server
View Single Post
Old 7th March 2006, 00:42
jeanjacquesjeanjacques jeanjacquesjeanjacques is offline
Join Date: Nov 2005
Posts: 60
Thanks: 0
Thanked 0 Times in 0 Posts
Unhappy Open DNS server


I'm a bit terrorized because i've just made a dns report on one of the domains hosted on my dns server and i received this warning: ERROR: One or more of your nameservers reports that it is an open DNS server. This usually means that anyone in the world can query it for domains it is not authoritative for (it is possible that the DNS server advertises that it does recursive lookups when it does not, but that shouldn't happen). This can cause an excessive load on your DNS server. Also, it is strongly discouraged to have a DNS server be both authoritative for your domain and be recursive (even if it is not open), due to the potential for cache poisoning (with no recursion, there is no cache, and it is impossible to poison it). Also, the bad guys could use your DNS server as part of an attack, by forging their IP address. Problem record(s) are:

Server reports that it will do recursive lookups.

I understand that this is really bad but i really don't know how to debug and arrange this situation ?
Does it mean that my server had been hacked ?

Thank you for helping me.
Reply With Quote
Sponsored Links