<html><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">hola,<div><br></div><div>Hubo una actulización del bug.</div><div><br></div><div>el bug sólo afecta a servidores autoritativos que son master para alguna zona. Si un servidor es sólo secundario, no está afectado. Ahora, BIND por defecto trae zonas como 127.in-addr.arpa configuradas, si es así, el servidor es aún vulnerable.</div><div><br></div><div>roque</div><div><br></div><div>fuente: <span class="Apple-style-span" style="color: rgb(84, 0, 0); "><a href="https://www.isc.org/node/474">https://www.isc.org/node/474</a></span></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br><div><div>On Jul 28, 2009, at 9:56 PM, Roque Gagliano wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">oscar,<div><br></div><div>toda versión anterior está EOL, así que mejor actualizar por las dudas.</div><div><br></div><div>fuente: <a href="https://www.isc.org/software/bind/versions">https://www.isc.org/software/bind/versions</a></div><div><br></div><div>slds</div><div>r.</div><div><br></div><div><br><div><div>On Jul 28, 2009, at 9:48 PM, Oscar Torres wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div><div><div apple-content-edited="true"><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0; "><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div><div><div>Buenas Noches a Todos, estas versiones solo afectan las versiones comentadas por Roque o todas las versiones 9 de Bind ???</div><div><br></div><div>Slds.</div><div><br></div><div><br class="Apple-interchange-newline">-- </div><div>Ing. Oscar Torres</div><div>Tel. (507) 560-3230</div><div>Fax. (507) 560-3148</div><div>Cel. (507) 6586-0370</div><div>Jefe de Redes y Comunicaciones</div><div>Lead Team Network and Telecommunications Department</div><div>Departamento de Redes y Comunicaciones</div><div>Universidad Tecnológica de Panamá</div><div>Dirección de Tecnologia de Información y Comunicaciones</div><div>NIC-PANAMA - UTP (Network Information Center - Panamá)</div><div>ccTLD.pa</div><div><br></div></div></div></div></span><br class="Apple-interchange-newline"><div><br></div><div><div>------------------------------------------------------------------------------------------------------------------------------------</div><div> Este mensaje (y sus adjuntos), en adelante "mensaje", ha sido enviado exclusivamente a su(s) destinatario(s) y es confidencial.</div><div>Si usted recibe este mensaje por error, por favor borrelo y comunique inmediatamente al remitente.</div><div>Toda utilizacion o publicacion, total o parcial, queda prohibida salvo autorizacion expresa. La UTP no podra ser considerada</div><div>responsable si el mensaje ha sido modificado y/o utilizado sin autorizacion.</div><div><br></div><div>-------------------------------------------------------------------------------------------------------------------------------------</div><div>This message (and any attachments), are confidential intended solely for the people whose addresses appear. If you have received this</div><div>message by error, please delete it and immediately notify the sender. Any use, dissemination or disclosure, either whole or</div><div>partial, without formal approval is prohibited. The UTP will not therefore be liable for the message if modified and/or used without</div><div>approval.</div><div>--------------------------------------------------------------------------------------------------------------------------------------</div></div></span> </div><br><div><div>On Jul 28, 2009, at 7:25 PM, Roque Gagliano wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">Amigos,<div><br></div><div>Hoy se descubrió una vulnerabilidad del bind que ocasiona que los servidores sufran un crash con un único paquete. El código para lanzar el ataque está disponible en la web por lo que el riesgo es grande. Abarca a BIND v. 9.4, 9.5 y 9.6</div><div><br></div><div>El anuncio de ISC se encuentra en:</div><div><blockquote type="cite"><blockquote type="cite"><a href="https://www.isc.org/node/474">https://www.isc.org/node/474</a></blockquote></blockquote><br></div><div>el primer anuncio del bug en:</div><div><blockquote type="cite"><blockquote type="cite"><a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538975">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538975</a></blockquote></blockquote></div><div><br></div><div><br></div><div>Roque</div><div><br></div><div>-----------</div><div><br></div><div>Dear friends,</div><div><br></div><div>Today a new vulnerability in BIND was announced and the code to explode it is available online.</div><div><br></div><div>The ISC announcement can be found here:</div><div><blockquote type="cite"><blockquote type="cite"><a href="https://www.isc.org/node/474">https://www.isc.org/node/474</a></blockquote></blockquote></div><div><br></div><div>The bug announcement here:</div><div><blockquote type="cite"><blockquote type="cite"><a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538975">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538975</a></blockquote></blockquote><br></div><div>Roque</div><div><br></div><div><div apple-content-edited="true"> <span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div><div>-------------------------------------------------------------</div><div>Roque Gagliano</div><div>LACNIC</div><div><a href="mailto:roque@lacnic.net">roque@lacnic.net</a></div><div>GPG Fingerprint: E929 06F4 D8CD 2AD8 9365 DB72 9E4F 964A 01E9 6CEE</div></div></div></span></div></span></div></span> </div><br></div></div>_______________________________________________<br>Seguridad mailing list<br><a href="mailto:Seguridad@lacnic.net">Seguridad@lacnic.net</a><br><a href="https://mail.lacnic.net/mailman/listinfo/seguridad">https://mail.lacnic.net/mailman/listinfo/seguridad</a><br></blockquote></div><br></div></div></div>_______________________________________________<br>Seguridad mailing list<br><a href="mailto:Seguridad@lacnic.net">Seguridad@lacnic.net</a><br><a href="https://mail.lacnic.net/mailman/listinfo/seguridad">https://mail.lacnic.net/mailman/listinfo/seguridad</a><br></blockquote></div><br><div apple-content-edited="true"> <span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div><div>-------------------------------------------------------------</div><div>Roque Gagliano</div><div>LACNIC</div><div><a href="mailto:roque@lacnic.net">roque@lacnic.net</a></div><div>GPG Fingerprint: E929 06F4 D8CD 2AD8 9365 DB72 9E4F 964A 01E9 6CEE</div></div></div></span></div></span></div></span> </div><br></div></div>_______________________________________________<br>LACNOG mailing list<br><a href="mailto:LACNOG@lacnic.net">LACNOG@lacnic.net</a><br><a href="https://mail.lacnic.net/mailman/listinfo/lacnog">https://mail.lacnic.net/mailman/listinfo/lacnog</a><br></blockquote></div><br><div apple-content-edited="true"> <span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div><div>-------------------------------------------------------------</div><div>Roque Gagliano</div><div>LACNIC</div><div><a href="mailto:roque@lacnic.net">roque@lacnic.net</a></div><div>GPG Fingerprint: E929 06F4 D8CD 2AD8 9365 DB72 9E4F 964A 01E9 6CEE</div></div></div></span></div></span></div></span> </div><br></div></body></html>