docker-bind
docker-bind copied to clipboard
Information Disclosure: Disable axfr requests
By default AXFR requests are enabled:
# dig axfr example.com @dns.server.com
This is considered to be a security issue because of the information disclosed:
https://beaglesecurity.com/blog/vulnerability/dns-zone-transfer.html
Could we disable it by default?:
options {
allow-transfer { "none"; };
...
}