- 论坛徽章:
- 1
|
请问如何防止Internet上的用户随便使用我的DNS
okay, 我測了一下.
在 namec.conf 加入如下設定:
allow-recursion { none; };
在修改之前, 連查兩下 bbs.chinaunix.net:
- [root@www chroot]# host -v bGbs.chinaunix.net 127.0.0.1
- Trying "bbs.chinaunix.net"
- Using domain server:
- Name: 127.0.0.1
- Address: 127.0.0.1#53
- Aliases:
- ;; ->;>;HEADER<<- opcode: QUERY, status: NOERROR, id: 30731
- ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 3
- ;; QUESTION SECTION:
- ;bbs.chinaunix.net. IN A
- ;; ANSWER SECTION:
- bbs.chinaunix.net. 10800 IN A 222.36.44.5
- ;; AUTHORITY SECTION:
- chinaunix.net. 10800 IN NS dns2.hichina.com.
- chinaunix.net. 10800 IN NS dns1.hichina.com.
- ;; ADDITIONAL SECTION:
- dns1.hichina.com. 172798 IN A 218.30.103.50
- dns1.hichina.com. 172798 IN A 218.30.103.49
- dns2.hichina.com. 172798 IN A 218.244.135.40
- Received 148 bytes from 127.0.0.1#53 in 3359 ms
- [root@www chroot]# host -v bbs.chinaunix.net 127.0.0.1
- Trying "bbs.chinaunix.net"
- Using domain server:
- Name: 127.0.0.1
- Address: 127.0.0.1#53
- Aliases:
- ;; ->;>;HEADER<<- opcode: QUERY, status: NOERROR, id: 39354
- ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 3
- ;; QUESTION SECTION:
- ;bbs.chinaunix.net. IN A
- ;; ANSWER SECTION:
- bbs.chinaunix.net. 10797 IN A 222.36.44.5
- ;; AUTHORITY SECTION:
- chinaunix.net. 10797 IN NS dns1.hichina.com.
- chinaunix.net. 10797 IN NS dns2.hichina.com.
- ;; ADDITIONAL SECTION:
- dns1.hichina.com. 172795 IN A 218.30.103.50
- dns1.hichina.com. 172795 IN A 218.30.103.49
- dns2.hichina.com. 172795 IN A 218.244.135.40
- Received 148 bytes from 127.0.0.1#53 in 12 ms
复制代码
從 TTL 的變化來看, 可以肯定是從 cache 得到的答案.
然後, 將 allow-recursion { none; }; 設起來之後:
- [root@www chroot]# host -v bbs.chinaunix.net 127.0.0.1
- Trying "bbs.chinaunix.net"
- Using domain server:
- Name: 127.0.0.1
- Address: 127.0.0.1#53
- Aliases:
- ;; ->;>;HEADER<<- opcode: QUERY, status: NOERROR, id: 25632
- ;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 13, ADDITIONAL: 13
- ;; QUESTION SECTION:
- ;bbs.chinaunix.net. IN A
- ;; AUTHORITY SECTION:
- . 518343 IN NS l.root-servers.net.
- . 518343 IN NS m.root-servers.net.
- . 518343 IN NS a.root-servers.net.
- . 518343 IN NS b.root-servers.net.
- . 518343 IN NS c.root-servers.net.
- . 518343 IN NS d.root-servers.net.
- . 518343 IN NS e.root-servers.net.
- . 518343 IN NS f.root-servers.net.
- . 518343 IN NS g.root-servers.net.
- . 518343 IN NS h.root-servers.net.
- . 518343 IN NS i.root-servers.net.
- . 518343 IN NS j.root-servers.net.
- . 518343 IN NS k.root-servers.net.
- ;; ADDITIONAL SECTION:
- a.root-servers.net. 604743 IN A 198.41.0.4
- b.root-servers.net. 604743 IN A 192.228.79.201
- c.root-servers.net. 604743 IN A 192.33.4.12
- d.root-servers.net. 604743 IN A 128.8.10.90
- e.root-servers.net. 604743 IN A 192.203.230.10
- f.root-servers.net. 604743 IN A 192.5.5.241
- g.root-servers.net. 604743 IN A 192.112.36.4
- h.root-servers.net. 604743 IN A 128.63.2.53
- i.root-servers.net. 604743 IN A 192.36.148.17
- j.root-servers.net. 604743 IN A 192.58.128.30
- k.root-servers.net. 604743 IN A 193.0.14.129
- l.root-servers.net. 604743 IN A 198.32.64.12
- m.root-servers.net. 604743 IN A 202.12.27.33
- Received 451 bytes from 127.0.0.1#53 in 21 ms
复制代码
看起來就不行了...
再取消這行:
- [root@www chroot]# host -v bbs.chinaunix.net 127.0.0.1
- Trying "bbs.chinaunix.net"
- Using domain server:
- Name: 127.0.0.1
- Address: 127.0.0.1#53
- Aliases:
- ;; ->;>;HEADER<<- opcode: QUERY, status: NOERROR, id: 41163
- ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 3
- ;; QUESTION SECTION:
- ;bbs.chinaunix.net. IN A
- ;; ANSWER SECTION:
- bbs.chinaunix.net. 10797 IN A 222.36.44.5
- ;; AUTHORITY SECTION:
- chinaunix.net. 10797 IN NS dns2.hichina.com.
- chinaunix.net. 10797 IN NS dns1.hichina.com.
- ;; ADDITIONAL SECTION:
- dns1.hichina.com. 172797 IN A 218.30.103.50
- dns1.hichina.com. 172797 IN A 218.30.103.49
- dns2.hichina.com. 172797 IN A 218.244.135.40
- Received 148 bytes from 127.0.0.1#53 in 12 ms
复制代码 |
|