<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.itcollege.ee/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Rvahtel</id>
	<title>ICO wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.itcollege.ee/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Rvahtel"/>
	<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php/Special:Contributions/Rvahtel"/>
	<updated>2026-05-09T13:40:19Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.45.1</generator>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30832</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30832"/>
		<updated>2011-05-09T10:05:06Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Autorid: Peep Binsol (AK31), Rene Vahtel (DK31)&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
&lt;br /&gt;
Open resolveriks nimetatakse nimeserverit, mis pakub nimelahendusteenust ka väljapoole oma administratiivset domeeni. Enamasti on open resolveriks puudulikult konfigureeritud DNS server. Ilma otsese vajaduseta tasuks kindlasti vältida open resolveri püstipanekut oma võrku.  Pole mingit vajadust pakkuda avalikku teenust kõigile.  See tähendab enamasti, et nimelahendust saab kasutada kogu internet. Teiseks saab kogu maailmale avatud DNS serverit kasutada DDOS rünnakute läbiviimiseks. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] [http://www.youtube.com/watch?v=UtEPfAgp2Xg&amp;amp;feature=related] Lisaks on avatud serverit rünnata vahemälu manipuleerimise teel. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] Nii satuksid ohtu konkreetse serveri teenuseid kasutavad kliendid.&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
Näide kuidas ACL&#039;i kasutades vältida nimeserveri muutumist open resolveriks.&lt;br /&gt;
named.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Windows 2008/2003 serveri seadistamine =&lt;br /&gt;
&lt;br /&gt;
;Seadsitamine kasutades käsurida:&lt;br /&gt;
# Ava käsurida (&amp;quot;command prompt&amp;quot;)&lt;br /&gt;
# Sisesta järgnevad käsud ning vajuta ENTER: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dnscmd &amp;lt;ServerName&amp;gt; /Config /NoRecursion {1|0}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
* dnscmd  - dns seaditamise programm&lt;br /&gt;
* ServerName  - server, mida soovitakse seadistada. Võib kasutada ka IP aadressi, kohaliku masina DNS serveri asemel võib kasutada ka punkti &amp;quot;.&amp;quot;&lt;br /&gt;
* /Config -  seadistamiseks vajalik parameeter.&lt;br /&gt;
* /NoRecursion- rekrusiivsete päringute lubamine ja keelamine. {1|0}. 1 off, 0 on. Vaikimisi on lubatud.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
;Seadistamine kasutajaliidesega&lt;br /&gt;
&lt;br /&gt;
# Ava DNS haldus (&amp;quot;DNS Manager&amp;quot;)&lt;br /&gt;
# Vali avanenud puust DNS server ning vajuta Omadused (&amp;quot;Properties&amp;quot;)&lt;br /&gt;
# Vali antud serverid Seaded (&amp;quot;Advanced properties&amp;quot;)&lt;br /&gt;
# Serveri valikute all tee linnuke kasti &amp;quot;Disable recursion&amp;quot;&lt;br /&gt;
&lt;br /&gt;
= Windows 2000 serveri seadistamine =&lt;br /&gt;
&lt;br /&gt;
Rekrusiivsete päringute keelamine:&lt;br /&gt;
&lt;br /&gt;
# Ava DNS (Start -&amp;gt; Programs, Administrative Tools -&amp;gt; DNS)&lt;br /&gt;
# Vali avanenud puust DNS server ning vajuta Omadused (&amp;quot;Properties&amp;quot;)&lt;br /&gt;
# Vali antud serverid Seaded (&amp;quot;Advanced properties&amp;quot;)&lt;br /&gt;
# Serveri valikute all tee linnuke kasti &amp;quot;Disable recursion&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
127.0.0.2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Juhul kui vastus on 127.0.0.2 siis on tegu openresolveriga.&lt;br /&gt;
&lt;br /&gt;
Teine variant (kontrollitakse masinas kasutatavad nimeserverit):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short amiopen.openresolvers.org TXT&lt;br /&gt;
&amp;quot;Your resolver at 193.40.56.245 is CLOSED&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Veebipõhine liides: http://dns.measurement-factory.com/cgi-bin/openresolvercheck.pl&lt;br /&gt;
&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
* Windowsi serverite seadistamine  [http://technet.microsoft.com/en-us/library/cc771738.aspx]  , [http://www.us-cert.gov/reading_room/DNS-recursion033006.pdf]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30831</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30831"/>
		<updated>2011-05-09T10:04:06Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Windows 2008/2003 serveri seadistamine */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Autorid: Peep Binsol (AK31), Rene Vahtel (DK31)&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
&lt;br /&gt;
Open resolveriks nimetatakse nimeserverit, mis pakub nimelahendusteenust ka väljapoole oma administratiivset domeeni. Enamasti on open resolveriks puudulikult konfigureeritud DNS server. Ilma otsese vajaduseta tasuks kindlasti vältida open resolveri püstipanekut oma võrku.  Pole mingit vajadust pakkuda avalikku teenust kõigile.  See tähendab enamasti, et nimelahendust saab kasutada kogu internet. Teiseks saab kogu maailmale avatud DNS serverit kasutada DDOS rünnakute läbiviimiseks. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] [http://www.youtube.com/watch?v=UtEPfAgp2Xg&amp;amp;feature=related] Lisaks on avatud serverit rünnata vahemälu manipuleerimise teel. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] Nii satuksid ohtu konkreetse serveri teenuseid kasutavad kliendid.&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
Näide kuidas ACL&#039;i kasutades vältida nimeserveri muutumist open resolveriks.&lt;br /&gt;
named.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Windows 2008/2003 serveri seadistamine =&lt;br /&gt;
&lt;br /&gt;
;Seadsitamine kasutades käsurida:&lt;br /&gt;
# Ava käsurida (&amp;quot;command prompt&amp;quot;)&lt;br /&gt;
# Sisesta järgnevad käsud ning vajuta ENTER: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dnscmd &amp;lt;ServerName&amp;gt; /Config /NoRecursion {1|0}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
* dnscmd  - dns seaditamise programm&lt;br /&gt;
* ServerName  - server, mida soovitakse seadistada. Võib kasutada ka IP aadressi, kohaliku masina DNS serveri asemel võib kasutada ka punkti &amp;quot;.&amp;quot;&lt;br /&gt;
* /Config -  seadistamiseks vajalik parameeter.&lt;br /&gt;
* /NoRecursion- rekrusiivsete päringute lubamine ja keelamine. {1|0}. 1 off, 0 on. Vaikimisi on lubatud.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
;Seadistamine kasutajaliidesega&lt;br /&gt;
&lt;br /&gt;
# Ava DNS haldus (&amp;quot;DNS Manager&amp;quot;)&lt;br /&gt;
# Vali avanenud puust DNS server ning vajuta Omadused (&amp;quot;Properties&amp;quot;)&lt;br /&gt;
# Vali antud serverid Seaded (&amp;quot;Advanced properties&amp;quot;)&lt;br /&gt;
# Serveri valikute all tee linnuke kasti &amp;quot;Disable recursion&amp;quot;&lt;br /&gt;
&lt;br /&gt;
= Windows 2000 serveri seadistamine =&lt;br /&gt;
&lt;br /&gt;
Rekrusiivsete päringute keelamine:&lt;br /&gt;
&lt;br /&gt;
# Ava DNS (Start -&amp;gt; Programs, Administrative Tools -&amp;gt; DNS)&lt;br /&gt;
# Vali avanenud puust DNS server ning vajuta Omadused (&amp;quot;Properties&amp;quot;)&lt;br /&gt;
# Vali antud serverid Seaded (&amp;quot;Advanced properties&amp;quot;)&lt;br /&gt;
# Serveri valikute all tee linnuke kasti &amp;quot;Disable recursion&amp;quot;&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
127.0.0.2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Juhul kui vastus on 127.0.0.2 siis on tegu openresolveriga.&lt;br /&gt;
&lt;br /&gt;
Teine variant (kontrollitakse masinas kasutatavad nimeserverit):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short amiopen.openresolvers.org TXT&lt;br /&gt;
&amp;quot;Your resolver at 193.40.56.245 is CLOSED&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Veebipõhine liides: http://dns.measurement-factory.com/cgi-bin/openresolvercheck.pl&lt;br /&gt;
&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
* Windowsi serverite seadistamine  [http://technet.microsoft.com/en-us/library/cc771738.aspx]  , [http://www.us-cert.gov/reading_room/DNS-recursion033006.pdf]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30830</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30830"/>
		<updated>2011-05-09T10:03:40Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Windows 2008/2003 serveri seadistamine */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Autorid: Peep Binsol (AK31), Rene Vahtel (DK31)&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
&lt;br /&gt;
Open resolveriks nimetatakse nimeserverit, mis pakub nimelahendusteenust ka väljapoole oma administratiivset domeeni. Enamasti on open resolveriks puudulikult konfigureeritud DNS server. Ilma otsese vajaduseta tasuks kindlasti vältida open resolveri püstipanekut oma võrku.  Pole mingit vajadust pakkuda avalikku teenust kõigile.  See tähendab enamasti, et nimelahendust saab kasutada kogu internet. Teiseks saab kogu maailmale avatud DNS serverit kasutada DDOS rünnakute läbiviimiseks. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] [http://www.youtube.com/watch?v=UtEPfAgp2Xg&amp;amp;feature=related] Lisaks on avatud serverit rünnata vahemälu manipuleerimise teel. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] Nii satuksid ohtu konkreetse serveri teenuseid kasutavad kliendid.&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
Näide kuidas ACL&#039;i kasutades vältida nimeserveri muutumist open resolveriks.&lt;br /&gt;
named.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Windows 2008/2003 serveri seadistamine =&lt;br /&gt;
&lt;br /&gt;
;Seadsitamine kasutades käsurida:&lt;br /&gt;
# Ava käsurida (&amp;quot;command prompt&amp;quot;)&lt;br /&gt;
# Sisesta järgnevad käsud ning vajuta ENTER: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dnscmd &amp;lt;ServerName&amp;gt; /Config /NoRecursion {1|0}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
* dnscmd  - dns seaditamise programm&lt;br /&gt;
* ServerName  - server, mida soovitakse seadistada. Võib kasutada ka IP aadressi, kohalik masina DNS serveri asemel võib kasutada ka punkti &amp;quot;.&amp;quot;&lt;br /&gt;
* /Config -  seadistamiseks vajalik parameeter.&lt;br /&gt;
* /NoRecursion- rekrusiivsete päringute lubamine ja keelamine. {1|0}. 1 off, 0 on. Vaikimisi on lubatud.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
;Seadistamine kasutajaliidesega&lt;br /&gt;
&lt;br /&gt;
# Ava DNS haldus (&amp;quot;DNS Manager&amp;quot;)&lt;br /&gt;
# Vali avanenud puust DNS server ning vajuta Omadused (&amp;quot;Properties&amp;quot;)&lt;br /&gt;
# Vali antud serverid Seaded (&amp;quot;Advanced properties&amp;quot;)&lt;br /&gt;
# Serveri valikute all tee linnuke kasti &amp;quot;Disable recursion&amp;quot;&lt;br /&gt;
&lt;br /&gt;
= Windows 2000 serveri seadistamine =&lt;br /&gt;
&lt;br /&gt;
Rekrusiivsete päringute keelamine:&lt;br /&gt;
&lt;br /&gt;
# Ava DNS (Start -&amp;gt; Programs, Administrative Tools -&amp;gt; DNS)&lt;br /&gt;
# Vali avanenud puust DNS server ning vajuta Omadused (&amp;quot;Properties&amp;quot;)&lt;br /&gt;
# Vali antud serverid Seaded (&amp;quot;Advanced properties&amp;quot;)&lt;br /&gt;
# Serveri valikute all tee linnuke kasti &amp;quot;Disable recursion&amp;quot;&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
127.0.0.2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Juhul kui vastus on 127.0.0.2 siis on tegu openresolveriga.&lt;br /&gt;
&lt;br /&gt;
Teine variant (kontrollitakse masinas kasutatavad nimeserverit):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short amiopen.openresolvers.org TXT&lt;br /&gt;
&amp;quot;Your resolver at 193.40.56.245 is CLOSED&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Veebipõhine liides: http://dns.measurement-factory.com/cgi-bin/openresolvercheck.pl&lt;br /&gt;
&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
* Windowsi serverite seadistamine  [http://technet.microsoft.com/en-us/library/cc771738.aspx]  , [http://www.us-cert.gov/reading_room/DNS-recursion033006.pdf]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30829</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30829"/>
		<updated>2011-05-09T10:02:46Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* WIndows 2000 serveri seadistamine */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Autorid: Peep Binsol (AK31), Rene Vahtel (DK31)&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
&lt;br /&gt;
Open resolveriks nimetatakse nimeserverit, mis pakub nimelahendusteenust ka väljapoole oma administratiivset domeeni. Enamasti on open resolveriks puudulikult konfigureeritud DNS server. Ilma otsese vajaduseta tasuks kindlasti vältida open resolveri püstipanekut oma võrku.  Pole mingit vajadust pakkuda avalikku teenust kõigile.  See tähendab enamasti, et nimelahendust saab kasutada kogu internet. Teiseks saab kogu maailmale avatud DNS serverit kasutada DDOS rünnakute läbiviimiseks. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] [http://www.youtube.com/watch?v=UtEPfAgp2Xg&amp;amp;feature=related] Lisaks on avatud serverit rünnata vahemälu manipuleerimise teel. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] Nii satuksid ohtu konkreetse serveri teenuseid kasutavad kliendid.&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
Näide kuidas ACL&#039;i kasutades vältida nimeserveri muutumist open resolveriks.&lt;br /&gt;
named.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Windows 2008/2003 serveri seadistamine =&lt;br /&gt;
&lt;br /&gt;
;Seadsitamine kasutades käsurida:&lt;br /&gt;
# Ava käsurida (&amp;quot;command prompt&amp;quot;)&lt;br /&gt;
# Sisesta järgnevad käsud ning vajuta ENTER: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dnscmd &amp;lt;ServerName&amp;gt; /Config /NoRecursion {1|0}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
* dnscmd  - dns seadsitamise programm&lt;br /&gt;
* ServerName  - server ,mida soovitakse seadistada. Võib kasutada ka IP aadressi, kohalik masina DNS serveri asemel võib kasutada ka punkti &amp;quot;.&amp;quot;&lt;br /&gt;
* /Config -  seadistamiseks vajalik parameeter.&lt;br /&gt;
* /NoRecursion- rekrusiivsete päringute lubamine ja keelamine. {1|0}. 1 off, 0 on. Vaikimisi on lubatud.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
;Seadistamine kasutajaliidesega&lt;br /&gt;
&lt;br /&gt;
# Ava DNS haldus (&amp;quot;DNS Manager&amp;quot;)&lt;br /&gt;
# Vali avanenud puust DNS server ning vajuta Omadused (&amp;quot;Properties&amp;quot;)&lt;br /&gt;
# Vali antud serverid Seaded (&amp;quot;Advanced properties&amp;quot;)&lt;br /&gt;
# Serveri valikute all tee linnuke kasti &amp;quot;Disable recursion&amp;quot;&lt;br /&gt;
&lt;br /&gt;
= Windows 2000 serveri seadistamine =&lt;br /&gt;
&lt;br /&gt;
Rekrusiivsete päringute keelamine:&lt;br /&gt;
&lt;br /&gt;
# Ava DNS (Start -&amp;gt; Programs, Administrative Tools -&amp;gt; DNS)&lt;br /&gt;
# Vali avanenud puust DNS server ning vajuta Omadused (&amp;quot;Properties&amp;quot;)&lt;br /&gt;
# Vali antud serverid Seaded (&amp;quot;Advanced properties&amp;quot;)&lt;br /&gt;
# Serveri valikute all tee linnuke kasti &amp;quot;Disable recursion&amp;quot;&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
127.0.0.2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Juhul kui vastus on 127.0.0.2 siis on tegu openresolveriga.&lt;br /&gt;
&lt;br /&gt;
Teine variant (kontrollitakse masinas kasutatavad nimeserverit):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short amiopen.openresolvers.org TXT&lt;br /&gt;
&amp;quot;Your resolver at 193.40.56.245 is CLOSED&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Veebipõhine liides: http://dns.measurement-factory.com/cgi-bin/openresolvercheck.pl&lt;br /&gt;
&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
* Windowsi serverite seadistamine  [http://technet.microsoft.com/en-us/library/cc771738.aspx]  , [http://www.us-cert.gov/reading_room/DNS-recursion033006.pdf]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30828</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30828"/>
		<updated>2011-05-09T10:02:32Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* WIndows 2008/2003 serveri seadistamine */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Autorid: Peep Binsol (AK31), Rene Vahtel (DK31)&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
&lt;br /&gt;
Open resolveriks nimetatakse nimeserverit, mis pakub nimelahendusteenust ka väljapoole oma administratiivset domeeni. Enamasti on open resolveriks puudulikult konfigureeritud DNS server. Ilma otsese vajaduseta tasuks kindlasti vältida open resolveri püstipanekut oma võrku.  Pole mingit vajadust pakkuda avalikku teenust kõigile.  See tähendab enamasti, et nimelahendust saab kasutada kogu internet. Teiseks saab kogu maailmale avatud DNS serverit kasutada DDOS rünnakute läbiviimiseks. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] [http://www.youtube.com/watch?v=UtEPfAgp2Xg&amp;amp;feature=related] Lisaks on avatud serverit rünnata vahemälu manipuleerimise teel. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] Nii satuksid ohtu konkreetse serveri teenuseid kasutavad kliendid.&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
Näide kuidas ACL&#039;i kasutades vältida nimeserveri muutumist open resolveriks.&lt;br /&gt;
named.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Windows 2008/2003 serveri seadistamine =&lt;br /&gt;
&lt;br /&gt;
;Seadsitamine kasutades käsurida:&lt;br /&gt;
# Ava käsurida (&amp;quot;command prompt&amp;quot;)&lt;br /&gt;
# Sisesta järgnevad käsud ning vajuta ENTER: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dnscmd &amp;lt;ServerName&amp;gt; /Config /NoRecursion {1|0}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
* dnscmd  - dns seadsitamise programm&lt;br /&gt;
* ServerName  - server ,mida soovitakse seadistada. Võib kasutada ka IP aadressi, kohalik masina DNS serveri asemel võib kasutada ka punkti &amp;quot;.&amp;quot;&lt;br /&gt;
* /Config -  seadistamiseks vajalik parameeter.&lt;br /&gt;
* /NoRecursion- rekrusiivsete päringute lubamine ja keelamine. {1|0}. 1 off, 0 on. Vaikimisi on lubatud.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
;Seadistamine kasutajaliidesega&lt;br /&gt;
&lt;br /&gt;
# Ava DNS haldus (&amp;quot;DNS Manager&amp;quot;)&lt;br /&gt;
# Vali avanenud puust DNS server ning vajuta Omadused (&amp;quot;Properties&amp;quot;)&lt;br /&gt;
# Vali antud serverid Seaded (&amp;quot;Advanced properties&amp;quot;)&lt;br /&gt;
# Serveri valikute all tee linnuke kasti &amp;quot;Disable recursion&amp;quot;&lt;br /&gt;
&lt;br /&gt;
= WIndows 2000 serveri seadistamine =&lt;br /&gt;
&lt;br /&gt;
Rekrusiivsete päringute keelamine:&lt;br /&gt;
&lt;br /&gt;
# Ava DNS (Start -&amp;gt; Programs, Administrative Tools -&amp;gt; DNS)&lt;br /&gt;
# Vali avanenud puust DNS server ning vajuta Omadused (&amp;quot;Properties&amp;quot;)&lt;br /&gt;
# Vali antud serverid Seaded (&amp;quot;Advanced properties&amp;quot;)&lt;br /&gt;
# Serveri valikute all tee linnuke kasti &amp;quot;Disable recursion&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
127.0.0.2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Juhul kui vastus on 127.0.0.2 siis on tegu openresolveriga.&lt;br /&gt;
&lt;br /&gt;
Teine variant (kontrollitakse masinas kasutatavad nimeserverit):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short amiopen.openresolvers.org TXT&lt;br /&gt;
&amp;quot;Your resolver at 193.40.56.245 is CLOSED&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Veebipõhine liides: http://dns.measurement-factory.com/cgi-bin/openresolvercheck.pl&lt;br /&gt;
&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
* Windowsi serverite seadistamine  [http://technet.microsoft.com/en-us/library/cc771738.aspx]  , [http://www.us-cert.gov/reading_room/DNS-recursion033006.pdf]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30826</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30826"/>
		<updated>2011-05-09T09:58:22Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Lingid */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Autorid: Peep Binsol (AK31), Rene Vahtel (DK31)&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
&lt;br /&gt;
Open resolveriks nimetatakse nimeserverit, mis pakub nimelahendusteenust ka väljapoole oma administratiivset domeeni. Enamasti on open resolveriks puudulikult konfigureeritud DNS server. Ilma otsese vajaduseta tasuks kindlasti vältida open resolveri püstipanekut oma võrku.  Pole mingit vajadust pakkuda avalikku teenust kõigile.  See tähendab enamasti, et nimelahendust saab kasutada kogu internet. Teiseks saab kogu maailmale avatud DNS serverit kasutada DDOS rünnakute läbiviimiseks. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] [http://www.youtube.com/watch?v=UtEPfAgp2Xg&amp;amp;feature=related] Lisaks on avatud serverit rünnata vahemälu manipuleerimise teel. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] Nii satuksid ohtu konkreetse serveri teenuseid kasutavad kliendid.&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
Näide kuidas ACL&#039;i kasutades vältida nimeserveri muutumist open resolveriks.&lt;br /&gt;
named.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= WIndows 2008/2003 serveri seadistamine =&lt;br /&gt;
&lt;br /&gt;
;Seadsitamine kasutades käsurida:&lt;br /&gt;
# Ava käsurida (&amp;quot;command prompt&amp;quot;)&lt;br /&gt;
# Sisesta järgnevad käsud ning vajuta ENTER: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dnscmd &amp;lt;ServerName&amp;gt; /Config /NoRecursion {1|0}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
* dnscmd  - dns seadsitamise programm&lt;br /&gt;
* ServerName  - server ,mida soovitakse seadistada. Võib kasutada ka IP aadressi, kohalik masina DNS serveri asemel võib kasutada ka punkti &amp;quot;.&amp;quot;&lt;br /&gt;
* /Config -  seadistamiseks vajalik parameeter.&lt;br /&gt;
* /NoRecursion- rekrusiivsete päringute lubamine ja keelamine. {1|0}. 1 off, 0 on. Vaikimisi on lubatud.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
;Seadistamine kasutajaliidesega&lt;br /&gt;
&lt;br /&gt;
# Ava DNS haldus (&amp;quot;DNS Manager&amp;quot;)&lt;br /&gt;
# Vali avanenud puust DNS server ning vajuta Omadused (&amp;quot;Properties&amp;quot;)&lt;br /&gt;
# Vali antud serverid Seaded (&amp;quot;Advanced properties&amp;quot;)&lt;br /&gt;
# Serveri valikute all tee linnuke kasti &amp;quot;Disable recursion&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= WIndows 2000 serveri seadistamine =&lt;br /&gt;
&lt;br /&gt;
Rekrusiivsete päringute keelamine:&lt;br /&gt;
&lt;br /&gt;
# Ava DNS (Start -&amp;gt; Programs, Administrative Tools -&amp;gt; DNS)&lt;br /&gt;
# Vali avanenud puust DNS server ning vajuta Omadused (&amp;quot;Properties&amp;quot;)&lt;br /&gt;
# Vali antud serverid Seaded (&amp;quot;Advanced properties&amp;quot;)&lt;br /&gt;
# Serveri valikute all tee linnuke kasti &amp;quot;Disable recursion&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
127.0.0.2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Juhul kui vastus on 127.0.0.2 siis on tegu openresolveriga.&lt;br /&gt;
&lt;br /&gt;
Teine variant (kontrollitakse masinas kasutatavad nimeserverit):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short amiopen.openresolvers.org TXT&lt;br /&gt;
&amp;quot;Your resolver at 193.40.56.245 is CLOSED&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Veebipõhine liides: http://dns.measurement-factory.com/cgi-bin/openresolvercheck.pl&lt;br /&gt;
&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
* Windowsi serverite seadistamine  [http://technet.microsoft.com/en-us/library/cc771738.aspx]  , [http://www.us-cert.gov/reading_room/DNS-recursion033006.pdf]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30825</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30825"/>
		<updated>2011-05-09T09:57:47Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Autorid: Peep Binsol (AK31), Rene Vahtel (DK31)&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
&lt;br /&gt;
Open resolveriks nimetatakse nimeserverit, mis pakub nimelahendusteenust ka väljapoole oma administratiivset domeeni. Enamasti on open resolveriks puudulikult konfigureeritud DNS server. Ilma otsese vajaduseta tasuks kindlasti vältida open resolveri püstipanekut oma võrku.  Pole mingit vajadust pakkuda avalikku teenust kõigile.  See tähendab enamasti, et nimelahendust saab kasutada kogu internet. Teiseks saab kogu maailmale avatud DNS serverit kasutada DDOS rünnakute läbiviimiseks. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] [http://www.youtube.com/watch?v=UtEPfAgp2Xg&amp;amp;feature=related] Lisaks on avatud serverit rünnata vahemälu manipuleerimise teel. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] Nii satuksid ohtu konkreetse serveri teenuseid kasutavad kliendid.&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
Näide kuidas ACL&#039;i kasutades vältida nimeserveri muutumist open resolveriks.&lt;br /&gt;
named.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= WIndows 2008/2003 serveri seadistamine =&lt;br /&gt;
&lt;br /&gt;
;Seadsitamine kasutades käsurida:&lt;br /&gt;
# Ava käsurida (&amp;quot;command prompt&amp;quot;)&lt;br /&gt;
# Sisesta järgnevad käsud ning vajuta ENTER: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dnscmd &amp;lt;ServerName&amp;gt; /Config /NoRecursion {1|0}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
* dnscmd  - dns seadsitamise programm&lt;br /&gt;
* ServerName  - server ,mida soovitakse seadistada. Võib kasutada ka IP aadressi, kohalik masina DNS serveri asemel võib kasutada ka punkti &amp;quot;.&amp;quot;&lt;br /&gt;
* /Config -  seadistamiseks vajalik parameeter.&lt;br /&gt;
* /NoRecursion- rekrusiivsete päringute lubamine ja keelamine. {1|0}. 1 off, 0 on. Vaikimisi on lubatud.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
;Seadistamine kasutajaliidesega&lt;br /&gt;
&lt;br /&gt;
# Ava DNS haldus (&amp;quot;DNS Manager&amp;quot;)&lt;br /&gt;
# Vali avanenud puust DNS server ning vajuta Omadused (&amp;quot;Properties&amp;quot;)&lt;br /&gt;
# Vali antud serverid Seaded (&amp;quot;Advanced properties&amp;quot;)&lt;br /&gt;
# Serveri valikute all tee linnuke kasti &amp;quot;Disable recursion&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= WIndows 2000 serveri seadistamine =&lt;br /&gt;
&lt;br /&gt;
Rekrusiivsete päringute keelamine:&lt;br /&gt;
&lt;br /&gt;
# Ava DNS (Start -&amp;gt; Programs, Administrative Tools -&amp;gt; DNS)&lt;br /&gt;
# Vali avanenud puust DNS server ning vajuta Omadused (&amp;quot;Properties&amp;quot;)&lt;br /&gt;
# Vali antud serverid Seaded (&amp;quot;Advanced properties&amp;quot;)&lt;br /&gt;
# Serveri valikute all tee linnuke kasti &amp;quot;Disable recursion&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
127.0.0.2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Juhul kui vastus on 127.0.0.2 siis on tegu openresolveriga.&lt;br /&gt;
&lt;br /&gt;
Teine variant (kontrollitakse masinas kasutatavad nimeserverit):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short amiopen.openresolvers.org TXT&lt;br /&gt;
&amp;quot;Your resolver at 193.40.56.245 is CLOSED&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Veebipõhine liides: http://dns.measurement-factory.com/cgi-bin/openresolvercheck.pl&lt;br /&gt;
&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
* Windowsi serverite seadistamine  [http://technet.microsoft.com/en-us/library/cc771738.aspx]&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30821</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30821"/>
		<updated>2011-05-09T09:52:04Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* WIndows 2008/2003 serveri seadistamine */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Autorid: Peep Binsol (AK31), Rene Vahtel (DK31)&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
&lt;br /&gt;
Open resolveriks nimetatakse nimeserverit, mis pakub nimelahendusteenust ka väljapoole oma administratiivset domeeni. Enamasti on open resolveriks puudulikult konfigureeritud DNS server. Ilma otsese vajaduseta tasuks kindlasti vältida open resolveri püstipanekut oma võrku.  Pole mingit vajadust pakkuda avalikku teenust kõigile.  See tähendab enamasti, et nimelahendust saab kasutada kogu internet. Teiseks saab kogu maailmale avatud DNS serverit kasutada DDOS rünnakute läbiviimiseks. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] [http://www.youtube.com/watch?v=UtEPfAgp2Xg&amp;amp;feature=related] Lisaks on avatud serverit rünnata vahemälu manipuleerimise teel. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] Nii satuksid ohtu konkreetse serveri teenuseid kasutavad kliendid.&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
Näide kuidas ACL&#039;i kasutades vältida nimeserveri muutumist open resolveriks.&lt;br /&gt;
named.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= WIndows 2008/2003 serveri seadistamine =&lt;br /&gt;
&lt;br /&gt;
;Seadsitamine kasutades käsurida:&lt;br /&gt;
# Ava käsurida (&amp;quot;command prompt&amp;quot;)&lt;br /&gt;
# Sisesta järgnevad käsud ning vajuta ENTER: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dnscmd &amp;lt;ServerName&amp;gt; /Config /NoRecursion {1|0}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
* dnscmd  - dns seadsitamise programm&lt;br /&gt;
* ServerName  - server ,mida soovitakse seadistada. Võib kasutada ka IP aadressi, kohalik masina DNS serveri asemel võib kasutada ka punkti &amp;quot;.&amp;quot;&lt;br /&gt;
* /Config -  seadistamiseks vajalik parameeter.&lt;br /&gt;
* /NoRecursion- rekrusiivsete päringute lubamine ja keelamine. {1|0}. 1 off, 0 on. Vaikimisi on lubatud.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
;Seadistamine kasutajaliidesega&lt;br /&gt;
&lt;br /&gt;
# Ava DNS haldus (&amp;quot;DNS Manager&amp;quot;)&lt;br /&gt;
# Vali avanenud puust DNS server ning vajuta Omadused (&amp;quot;Properties&amp;quot;)&lt;br /&gt;
# Vali antud serverid Seaded (&amp;quot;Advanced properties&amp;quot;)&lt;br /&gt;
# Serveri valikute all tee linnuke kasti &amp;quot;Disable recursion&amp;quot;&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
127.0.0.2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Juhul kui vastus on 127.0.0.2 siis on tegu openresolveriga.&lt;br /&gt;
&lt;br /&gt;
Teine variant (kontrollitakse masinas kasutatavad nimeserverit):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short amiopen.openresolvers.org TXT&lt;br /&gt;
&amp;quot;Your resolver at 193.40.56.245 is CLOSED&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Veebipõhine liides: http://dns.measurement-factory.com/cgi-bin/openresolvercheck.pl&lt;br /&gt;
&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
* Windowsi serverite seadistamine  [http://technet.microsoft.com/en-us/library/cc771738.aspx]&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30820</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30820"/>
		<updated>2011-05-09T09:51:02Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* WIndows 2008/2003 serveri seadistamine */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Autorid: Peep Binsol (AK31), Rene Vahtel (DK31)&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
&lt;br /&gt;
Open resolveriks nimetatakse nimeserverit, mis pakub nimelahendusteenust ka väljapoole oma administratiivset domeeni. Enamasti on open resolveriks puudulikult konfigureeritud DNS server. Ilma otsese vajaduseta tasuks kindlasti vältida open resolveri püstipanekut oma võrku.  Pole mingit vajadust pakkuda avalikku teenust kõigile.  See tähendab enamasti, et nimelahendust saab kasutada kogu internet. Teiseks saab kogu maailmale avatud DNS serverit kasutada DDOS rünnakute läbiviimiseks. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] [http://www.youtube.com/watch?v=UtEPfAgp2Xg&amp;amp;feature=related] Lisaks on avatud serverit rünnata vahemälu manipuleerimise teel. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] Nii satuksid ohtu konkreetse serveri teenuseid kasutavad kliendid.&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
Näide kuidas ACL&#039;i kasutades vältida nimeserveri muutumist open resolveriks.&lt;br /&gt;
named.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= WIndows 2008/2003 serveri seadistamine =&lt;br /&gt;
&lt;br /&gt;
;Seadsitamine kasutades käsurida:&lt;br /&gt;
1. Ava käsurida (&amp;quot;command prompt&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
2. Sisesta järgnevad käsud ning vajuta ENTER: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dnscmd &amp;lt;ServerName&amp;gt; /Config /NoRecursion {1|0}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
* dnscmd  - dns seadsitamise programm&lt;br /&gt;
* ServerName  - server ,mida soovitakse seadistada. Võib kasutada ka IP aadressi, kohalik masina DNS serveri asemel võib kasutada ka punkti &amp;quot;.&amp;quot;&lt;br /&gt;
* /Config -  seadistamiseks vajalik parameeter.&lt;br /&gt;
* /NoRecursion- rekrusiivsete päringute lubamine ja keelamine. {1|0}. 1 off, 0 on. Vaikimisi on lubatud.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
;Seadistamine kasutajaliidesega&lt;br /&gt;
&lt;br /&gt;
1. Ava DNS haldus (&amp;quot;DNS Manager&amp;quot;)&lt;br /&gt;
2. Vali avanenud puust DNS server ning vajuta Omadused (&amp;quot;Properties&amp;quot;)&lt;br /&gt;
3. Vali antud serverid Seaded (&amp;quot;Advanced properties&amp;quot;)&lt;br /&gt;
4. Serveri valikute all tee linnuke kasti &amp;quot;Disable recursion&amp;quot;&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
127.0.0.2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Juhul kui vastus on 127.0.0.2 siis on tegu openresolveriga.&lt;br /&gt;
&lt;br /&gt;
Teine variant (kontrollitakse masinas kasutatavad nimeserverit):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short amiopen.openresolvers.org TXT&lt;br /&gt;
&amp;quot;Your resolver at 193.40.56.245 is CLOSED&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Veebipõhine liides: http://dns.measurement-factory.com/cgi-bin/openresolvercheck.pl&lt;br /&gt;
&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
* Windowsi serverite seadistamine  [http://technet.microsoft.com/en-us/library/cc771738.aspx]&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30819</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30819"/>
		<updated>2011-05-09T09:42:38Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Lingid */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Autorid: Peep Binsol (AK31), Rene Vahtel (DK31)&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
&lt;br /&gt;
Open resolveriks nimetatakse nimeserverit, mis pakub nimelahendusteenust ka väljapoole oma administratiivset domeeni. Enamasti on open resolveriks puudulikult konfigureeritud DNS server. Ilma otsese vajaduseta tasuks kindlasti vältida open resolveri püstipanekut oma võrku.  Pole mingit vajadust pakkuda avalikku teenust kõigile.  See tähendab enamasti, et nimelahendust saab kasutada kogu internet. Teiseks saab kogu maailmale avatud DNS serverit kasutada DDOS rünnakute läbiviimiseks. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] [http://www.youtube.com/watch?v=UtEPfAgp2Xg&amp;amp;feature=related] Lisaks on avatud serverit rünnata vahemälu manipuleerimise teel. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] Nii satuksid ohtu konkreetse serveri teenuseid kasutavad kliendid.&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
Näide kuidas ACL&#039;i kasutades vältida nimeserveri muutumist open resolveriks.&lt;br /&gt;
named.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= WIndows 2008/2003 serveri seadistamine =&lt;br /&gt;
&lt;br /&gt;
;Käsurealt:&lt;br /&gt;
1. Ava käsurida (&amp;quot;command prompt&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
2. Sisesta järgnevad käsud ning vajuta ENTER: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dnscmd &amp;lt;ServerName&amp;gt; /Config /NoRecursion {1|0}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
* dnscmd  - dns seadsitamise programm&lt;br /&gt;
* ServerName  - server ,mida soovitakse seadistada. Võib kasutada ka IP aadressi, kohalik masina DNS serveri asemel võib kasutada ka punkti &amp;quot;.&amp;quot;&lt;br /&gt;
* /Config -  seadistamiseks vajalik parameeter.&lt;br /&gt;
* /NoRecursion- rekrusiivsete päringute lubamine ja keelamine. {1|0}. 1 off, 0 on. Vaikimisi on lubatud. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
127.0.0.2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Juhul kui vastus on 127.0.0.2 siis on tegu openresolveriga.&lt;br /&gt;
&lt;br /&gt;
Teine variant (kontrollitakse masinas kasutatavad nimeserverit):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short amiopen.openresolvers.org TXT&lt;br /&gt;
&amp;quot;Your resolver at 193.40.56.245 is CLOSED&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Veebipõhine liides: http://dns.measurement-factory.com/cgi-bin/openresolvercheck.pl&lt;br /&gt;
&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
* Windowsi serverite seadistamine  [http://technet.microsoft.com/en-us/library/cc771738.aspx]&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30818</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30818"/>
		<updated>2011-05-09T09:41:40Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Autorid: Peep Binsol (AK31), Rene Vahtel (DK31)&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
&lt;br /&gt;
Open resolveriks nimetatakse nimeserverit, mis pakub nimelahendusteenust ka väljapoole oma administratiivset domeeni. Enamasti on open resolveriks puudulikult konfigureeritud DNS server. Ilma otsese vajaduseta tasuks kindlasti vältida open resolveri püstipanekut oma võrku.  Pole mingit vajadust pakkuda avalikku teenust kõigile.  See tähendab enamasti, et nimelahendust saab kasutada kogu internet. Teiseks saab kogu maailmale avatud DNS serverit kasutada DDOS rünnakute läbiviimiseks. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] [http://www.youtube.com/watch?v=UtEPfAgp2Xg&amp;amp;feature=related] Lisaks on avatud serverit rünnata vahemälu manipuleerimise teel. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] Nii satuksid ohtu konkreetse serveri teenuseid kasutavad kliendid.&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
Näide kuidas ACL&#039;i kasutades vältida nimeserveri muutumist open resolveriks.&lt;br /&gt;
named.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= WIndows 2008/2003 serveri seadistamine =&lt;br /&gt;
&lt;br /&gt;
;Käsurealt:&lt;br /&gt;
1. Ava käsurida (&amp;quot;command prompt&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
2. Sisesta järgnevad käsud ning vajuta ENTER: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dnscmd &amp;lt;ServerName&amp;gt; /Config /NoRecursion {1|0}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
* dnscmd  - dns seadsitamise programm&lt;br /&gt;
* ServerName  - server ,mida soovitakse seadistada. Võib kasutada ka IP aadressi, kohalik masina DNS serveri asemel võib kasutada ka punkti &amp;quot;.&amp;quot;&lt;br /&gt;
* /Config -  seadistamiseks vajalik parameeter.&lt;br /&gt;
* /NoRecursion- rekrusiivsete päringute lubamine ja keelamine. {1|0}. 1 off, 0 on. Vaikimisi on lubatud. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
127.0.0.2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Juhul kui vastus on 127.0.0.2 siis on tegu openresolveriga.&lt;br /&gt;
&lt;br /&gt;
Teine variant (kontrollitakse masinas kasutatavad nimeserverit):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short amiopen.openresolvers.org TXT&lt;br /&gt;
&amp;quot;Your resolver at 193.40.56.245 is CLOSED&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Veebipõhine liides: http://dns.measurement-factory.com/cgi-bin/openresolvercheck.pl&lt;br /&gt;
&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30817</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=30817"/>
		<updated>2011-05-09T09:40:35Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Autorid: Peep Binsol (AK31), Rene Vahtel (DK31)&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
&lt;br /&gt;
Open resolveriks nimetatakse nimeserverit, mis pakub nimelahendusteenust ka väljapoole oma administratiivset domeeni. Enamasti on open resolveriks puudulikult konfigureeritud DNS server. Ilma otsese vajaduseta tasuks kindlasti vältida open resolveri püstipanekut oma võrku.  Pole mingit vajadust pakkuda avalikku teenust kõigile.  See tähendab enamasti, et nimelahendust saab kasutada kogu internet. Teiseks saab kogu maailmale avatud DNS serverit kasutada DDOS rünnakute läbiviimiseks. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] [http://www.youtube.com/watch?v=UtEPfAgp2Xg&amp;amp;feature=related] Lisaks on avatud serverit rünnata vahemälu manipuleerimise teel. [http://www.youtube.com/watch?v=1d1tUefYn4U&amp;amp;feature=related] Nii satuksid ohtu konkreetse serveri teenuseid kasutavad kliendid.&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
Näide kuidas ACL&#039;i kasutades vältida nimeserveri muutumist open resolveriks.&lt;br /&gt;
named.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== WIndows 2008 serveri seadistamine ===&lt;br /&gt;
&lt;br /&gt;
;Käsurealt:&lt;br /&gt;
1. Ava käsurida (&amp;quot;command prompt&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
2. Sisesta järgnevad käsud ning vajuta ENTER: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dnscmd &amp;lt;ServerName&amp;gt; /Config /NoRecursion {1|0}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
* dnscmd  - dns seadsitamise programm&lt;br /&gt;
* ServerName  - server ,mida soovitakse seadistada. Võib kasutada ka IP aadressi, kohalik masina DNS serveri asemel võib kasutada ka punkti &amp;quot;.&amp;quot;&lt;br /&gt;
* /Config -  seadistamiseks vajalik parameeter.&lt;br /&gt;
* /NoRecursion- rekrusiivsete päringute lubamine ja keelamine. {1|0}. 1 off, 0 on. Vaikimisi on lubatud. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
127.0.0.2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Juhul kui vastus on 127.0.0.2 siis on tegu openresolveriga.&lt;br /&gt;
&lt;br /&gt;
Teine variant (kontrollitakse masinas kasutatavad nimeserverit):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short amiopen.openresolvers.org TXT&lt;br /&gt;
&amp;quot;Your resolver at 193.40.56.245 is CLOSED&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Veebipõhine liides: http://dns.measurement-factory.com/cgi-bin/openresolvercheck.pl&lt;br /&gt;
&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23638</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23638"/>
		<updated>2011-03-12T17:42:40Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Teema võetud - Peep Binsol, Rene Vahtel&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
name.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
127.0.0.2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Juhul kui vastus on 127.0.0.2 siis on tegu openresolveriga.&lt;br /&gt;
&lt;br /&gt;
Teine variant (kontrollitakse masinas kasutatavad nimeserverit):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short amiopen.openresolvers.org TXT&lt;br /&gt;
&amp;quot;Your resolver at 193.40.56.245 is CLOSED&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Veebipõhine liides: http://dns.measurement-factory.com/cgi-bin/openresolvercheck.pl&lt;br /&gt;
&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23637</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23637"/>
		<updated>2011-03-12T17:30:31Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Open resolver test */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Teema võetud - Peep Binsol, Rene Vahtel&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
name.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
127.0.0.2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Juhul kui vastus on 127.0.0.2 siis on tegu openresolveriga.&lt;br /&gt;
&lt;br /&gt;
Teine variant (kontrollitakse masinas kasutatavad nimeserverit):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short amiopen.openresolvers.org TXT&lt;br /&gt;
&amp;quot;Your resolver at 193.40.56.245 is CLOSED&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Veebipõhine liides: http://dns.measurement-factory.com/cgi-bin/openresolvercheck.pl&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23636</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23636"/>
		<updated>2011-03-12T17:28:45Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Open resolver test */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Teema võetud - Peep Binsol, Rene Vahtel&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
name.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
127.0.0.2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Juhul kui vastus on 127.0.0.2 siis on tegu openresolveriga.&lt;br /&gt;
&lt;br /&gt;
Teine variant (kontrollitakse masinas kasutatavad nimeserverit):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short amiopen.openresolvers.org TXT&lt;br /&gt;
&amp;quot;Your resolver at 193.40.56.245 is CLOSED&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Veebipõhine liides: http://dns.measurement-factory.com/cgi-bin/openresolvercheck.pl&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23635</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23635"/>
		<updated>2011-03-12T17:27:50Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Open resolver test */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Teema võetud - Peep Binsol, Rene Vahtel&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
name.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
127.0.0.2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Juhul kui vastus on 127.0.0.2 siis on tegu openresolveriga.&lt;br /&gt;
&lt;br /&gt;
Teine variant (kontrollitakse masinas kasutatavad nimeserverit):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short amiopen.openresolvers.org TXT&lt;br /&gt;
&amp;quot;Your resolver at 193.40.56.245 is CLOSED&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23634</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23634"/>
		<updated>2011-03-12T17:27:35Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Open resolver test */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Teema võetud - Peep Binsol, Rene Vahtel&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
name.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
127.0.0.2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Juhul kui vastus on 127.0.0.2 siis on tegu openresolveriga.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Teine variant (kontrollitakse masinas kasutatavad nimeserverit):&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short amiopen.openresolvers.org TXT&lt;br /&gt;
&amp;quot;Your resolver at 193.40.56.245 is CLOSED&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23633</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23633"/>
		<updated>2011-03-12T17:26:14Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Open resolver test */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Teema võetud - Peep Binsol, Rene Vahtel&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
name.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
127.0.0.2&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Juhul kui vastus on 127.0.0.2 siis on tegu openresolveriga.&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23632</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23632"/>
		<updated>2011-03-12T17:25:25Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Lingid */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Teema võetud - Peep Binsol, Rene Vahtel&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
* Openresolver [http://dns.measurement-factory.com/surveys/openresolvers.html]&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
name.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23631</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23631"/>
		<updated>2011-03-12T17:24:55Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Open resolver test */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Teema võetud - Peep Binsol, Rene Vahtel&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
name.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
* Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23630</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23630"/>
		<updated>2011-03-12T17:23:41Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Open resolver test */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Teema võetud - Peep Binsol, Rene Vahtel&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
name.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
Käsurealt küsimine kasutades dig programmi:&lt;br /&gt;
Kontrollime nimeserverit 193.40.254.227&lt;br /&gt;
dig +short 227.254.40.193.dnsbl.openresolvers.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23629</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23629"/>
		<updated>2011-03-12T17:12:06Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Lingid */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Teema võetud - Peep Binsol, Rene Vahtel&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
=Lingid=&lt;br /&gt;
* Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
* konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
name.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23628</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23628"/>
		<updated>2011-03-12T17:11:51Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Lingid */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Teema võetud - Peep Binsol, Rene Vahtel&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
=Lingid=&lt;br /&gt;
Ubuntu Bind9 konfigureerimine [https://help.ubuntu.com/community/BIND9ServerHowto]&lt;br /&gt;
konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
name.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23627</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23627"/>
		<updated>2011-03-12T17:10:57Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Bind9 konfigureerimine */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Teema võetud - Peep Binsol, Rene Vahtel&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
=Lingid=&lt;br /&gt;
&lt;br /&gt;
konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
name.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
* allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
* allow-query - kas päringud on lubatud&lt;br /&gt;
* allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23626</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23626"/>
		<updated>2011-03-12T17:09:51Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Bind9 konfigureerimine */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Teema võetud - Peep Binsol, Rene Vahtel&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
=Lingid=&lt;br /&gt;
&lt;br /&gt;
konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
name.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
acl - access control list, nimekiri võrkudest või ip aadressidest&lt;br /&gt;
allow-recursion - kas päringud on lubatud &amp;quot;forwarders&amp;quot; nimeserveritesse&lt;br /&gt;
allow-query - kas päringud on lubatud&lt;br /&gt;
allow-transafer - kas tsooni transfer on lubatud&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23625</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23625"/>
		<updated>2011-03-12T17:07:25Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Bind9 konfigureerimine */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Teema võetud - Peep Binsol, Rene Vahtel&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
=Lingid=&lt;br /&gt;
&lt;br /&gt;
konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
&lt;br /&gt;
name.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23624</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23624"/>
		<updated>2011-03-12T17:07:15Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Open resolver test */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Teema võetud - Peep Binsol, Rene Vahtel&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
=Lingid=&lt;br /&gt;
&lt;br /&gt;
konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
	<entry>
		<id>https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23623</id>
		<title>Open resolver</title>
		<link rel="alternate" type="text/html" href="https://wiki.itcollege.ee/index.php?title=Open_resolver&amp;diff=23623"/>
		<updated>2011-03-12T17:06:49Z</updated>

		<summary type="html">&lt;p&gt;Rvahtel: /* Bind9 konfigureerimine */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Teema võetud - Peep Binsol, Rene Vahtel&lt;br /&gt;
&lt;br /&gt;
=Sissejuhatus=&lt;br /&gt;
=Lingid=&lt;br /&gt;
&lt;br /&gt;
konfinäide: [http://jazzymarketing.com/main/0904/open-resolver-securing-bind-server]&lt;br /&gt;
&lt;br /&gt;
=Bind9 konfigureerimine=&lt;br /&gt;
=Open resolver test=&lt;br /&gt;
&lt;br /&gt;
name.conf.options näitefail&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
acl me {192.168.7.0/24;};&lt;br /&gt;
&lt;br /&gt;
options {&lt;br /&gt;
        directory &amp;quot;/var/cache/bind&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
         forwarders {&lt;br /&gt;
                8.8.8.8;&lt;br /&gt;
                8.8.4.4;&lt;br /&gt;
         };&lt;br /&gt;
&lt;br /&gt;
        allow-recursion { me; };&lt;br /&gt;
        allow-query { me; };&lt;br /&gt;
        allow-transfer { me; };&lt;br /&gt;
&lt;br /&gt;
        auth-nxdomain no;    # conform to RFC1035&lt;br /&gt;
        listen-on-v6 { any; };&lt;br /&gt;
};&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:IT infrastruktuuri teenused]]&lt;br /&gt;
[[Category:Operatsioonisüsteemide administreerimine ja sidumine]]&lt;/div&gt;</summary>
		<author><name>Rvahtel</name></author>
	</entry>
</feed>