From a1f38bd3765fcc84e1254970482c53bba4d99a45 Mon Sep 17 00:00:00 2001 From: Xin Li Date: Fri, 16 Dec 2011 13:27:56 -0800 Subject: [PATCH 13/65] Apply dnsready accept filter when available. This mitigates DoS attack. --- contrib/bind9/bin/named/interfacemgr.c | 2 +- 1 files changed, 1 insertions(+), 1 deletions(-) diff --git a/contrib/bind9/bin/named/interfacemgr.c b/contrib/bind9/bin/named/interfacemgr.c index 513fb24..81555f0 100644 --- a/contrib/bind9/bin/named/interfacemgr.c +++ b/contrib/bind9/bin/named/interfacemgr.c @@ -328,7 +328,7 @@ ns_interface_accepttcp(ns_interface_t *ifp) { * If/when there a multiple filters listen to the * result. */ - (void)isc_socket_filter(ifp->tcpsocket, "dataready"); + (void)isc_socket_filter(ifp->tcpsocket, "dnsready"); result = ns_clientmgr_createclients(ifp->clientmgr, ifp->ntcptarget, ifp, -- 1.7.8.3