BIND DNS Server Hloov tshiab 9.11.18, 9.16.2 thiab 9.17.1

Tshaj tawm Kev kho tshiab rau cov ceg ruaj khov ntawm BIND DNS server 9.11.18 thiab 9.16.2, nrog rau cov ceg sim 9.17.1, uas yog nyob rau hauv kev txhim kho. Hauv kev tawm tshiab tshem tawm teeb meem kev ruaj ntseg cuam tshuam nrog kev tiv thaiv tsis zoo tiv thaiv kev tawm tsam "DNS rebindingΒ» thaum ua haujlwm nyob rau hauv hom ntawm DNS neeg rau zaub mov xa mus thov (cov "forwarders" thaiv hauv qhov chaw). Tsis tas li ntawd, kev ua haujlwm tau ua tiav los txo qhov loj ntawm cov ntawv kos npe digital khaws cia hauv lub cim xeeb rau DNSSEC - tus lej ntawm cov yuam sij tau raug txo mus rau 4 rau txhua cheeb tsam, uas yog txaus nyob rau hauv 99% ntawm cov neeg mob.

Cov txheej txheem "DNS rebinding" tso cai, thaum tus neeg siv qhib ib nplooj ntawv hauv qhov browser, tsim kom muaj kev sib txuas WebSocket rau kev pabcuam hauv lub network ntawm lub network sab hauv uas tsis tuaj yeem nkag ncaj qha los ntawm Is Taws Nem. Txhawm rau hla kev tiv thaiv siv hauv browsers tawm tsam mus dhau qhov kev nthuav dav ntawm cov npe tam sim no (cross-origin), hloov lub npe tswv hauv DNS. Tus neeg tawm tsam DNS server tau teeb tsa kom xa tawm ob qhov chaw nyob IP ib qho los ntawm ib qho: thawj qhov kev thov xa tus IP tiag tiag ntawm tus neeg rau zaub mov nrog nplooj ntawv, thiab tom qab thov rov qab qhov chaw nyob sab hauv ntawm lub cuab yeej (piv txwv li, 192.168.10.1).

Lub sijhawm nyob (TTL) rau thawj cov lus teb yog teem rau tus nqi tsawg kawg nkaus, yog li thaum qhib nplooj ntawv, tus browser txiav txim siab tus IP tiag tiag ntawm tus neeg tua neeg lub server thiab thauj cov ntsiab lus ntawm nplooj ntawv. Nplooj ntawv sau JavaScript code uas tos kom TTL tas sij hawm thiab xa daim ntawv thov thib ob, uas tam sim no txheeb xyuas tus tswv tsev li 192.168.10.1. Qhov no tso cai rau JavaScript nkag mus rau ib qho kev pabcuam hauv lub network hauv zos, hla qhov kev txwv hla ntawm keeb kwm. kev tiv thaiv tawm tsam xws li kev tawm tsam hauv BIND yog raws li thaiv cov servers sab nraud los ntawm rov qab IP chaw nyob ntawm lub network sab hauv tam sim no lossis CNAME aliases rau cov chaw hauv zos siv qhov tsis lees paub- teb-chaw nyob thiab tsis kam lees- teb-aliases nqis.

Tau qhov twg los: opennet.ru

Ntxiv ib saib