Date:  Fri, 7 Nov 2008 10:52:41 -0800
Re: Cache snooping attacks, bind
Sent: Friday, November 07, 2008 4:08 AM
Re: Cache snooping attacks, bind

>I am reposting to see if anyone can help. Can BIND be upgraded to 
> 9.4.1-P1 without issue/conflict with the GUI?
> We really need the 'allow-query-cache' option to maintain PCI compliance 
> and this is not available until the 9.4.1-P1 release.
> Thanks,
> Brian


All you need to do is not allow recursion for IPs outside your network. 

For example my /var/named/chroot/etc/named.conf      begins with:

options {
  directory "/var/named";
  // spoof version for a little more security via obscurity
  version "100.102.105";
  forwarders {;;};
  // zone transfer access denied
  allow-transfer {;; };
  allow-recursion {;; };
  // recursion allowed

