<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DNS &#8211; 21點情報網</title>
	<atom:link href="https://ailog.tw/lifelog/tag/dns/feed/" rel="self" type="application/rss+xml" />
	<link>https://ailog.tw/lifelog</link>
	<description></description>
	<lastBuildDate>Tue, 12 Aug 2025 05:13:24 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>
	<item>
		<title>透過指令模式新增Windows DNS的A紀錄</title>
		<link>https://ailog.tw/lifelog/2025/08/12/win-dns-cmd/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Tue, 12 Aug 2025 05:13:12 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[command line]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[指令]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=18084</guid>

					<description><![CDATA[如有大量的資料需要手動建立到windows DNS服務中，聽起來也是相當累人的事情，透過指令模式即可結合批次檔 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2025/08/12/win-dns-cmd/" class="more-link">閱讀全文<span class="screen-reader-text">〈透過指令模式新增Windows DNS的A紀錄〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>如有大量的資料需要手動建立到windows DNS服務中，聽起來也是相當累人的事情，透過指令模式即可結合批次檔案快速進行，快來了解如何操作吧!</p>
<p><span id="more-18084"></span></p>
<p><span style="font-family: verdana, geneva;">建立DNS A紀錄的範例語</span><span style="font-family: verdana, geneva;">法:</span></p>
<pre>dnscmd /recordadd ailog.tw web A 168.95.1.1</pre>
<p>透過上面的語法可以建立</p>
<p>web.ailog.tw = 168.95.1.1 的A紀錄對應。</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Windows DNS Server次要主機建置</title>
		<link>https://ailog.tw/lifelog/2024/10/29/win-secondary-dns/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Tue, 29 Oct 2024 05:29:11 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[primary]]></category>
		<category><![CDATA[secondary]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=17672</guid>

					<description><![CDATA[有時異地的辦公室希望建立一台DNS來加快解析或不希望與總公司失聯時，會因DNS失聯導致斷網，這些情境都很適合架 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2024/10/29/win-secondary-dns/" class="more-link">閱讀全文<span class="screen-reader-text">〈Windows DNS Server次要主機建置〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-family: verdana, geneva;">有時異地的辦公室希望建立一台DNS來加快解析或不希望與總公司失聯時，會因DNS失聯導致斷網，這些情境都很適合架設次要DNS主機，底下就快跟著小編一起來了解如何架設吧!</span></p>
<p><span id="more-17672"></span></p>
<p><span style="font-family: verdana, geneva;">1、模擬情境</span><br />
<span style="font-family: verdana, geneva;">(1)、domain name：abc.com.tw</span><br />
<span style="font-family: verdana, geneva;">(2)、主要的DNS服務(或是AD主機)IP為：192.168.10.1</span><br />
<span style="font-family: verdana, geneva;">(3)、異地的DNS主機IP為192.168.30.1</span><br />
<span style="font-family: verdana, geneva;">(4)、以上所敘述的主機均為Windows Server</span></p>
<p><span style="font-family: verdana, geneva;">2、先在異地的DNS主機上安裝DNS服務</span><br />
<span style="font-family: verdana, geneva;">※以下的語法均為powershell指令，並在192.168.30.1的dns次要主機上執行</span><br />
<span style="font-family: verdana, geneva;">(1)、安裝DNS服務</span></p>
<pre>Install-WindowsFeature -Name DNS -IncludeManagementTools</pre>
<p><span style="font-family: verdana, geneva;">(2)、確認安裝狀態</span></p>
<pre>Get-WindowsFeature -Name DNS</pre>
<p><img fetchpriority="high" decoding="async" class="alignnone wp-image-17674 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2024/10/win-dns-02.png" alt="" width="814" height="171" srcset="https://ailog.tw/lifelog/wp-content/uploads/2024/10/win-dns-02.png 814w, https://ailog.tw/lifelog/wp-content/uploads/2024/10/win-dns-02-300x63.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2024/10/win-dns-02-768x161.png 768w" sizes="(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></p>
<p>※在Install State欄位顯示「Installed」的話代表有順利安裝成功</p>
<p><span style="font-family: verdana, geneva;">3、設定DNS紀錄同步作業<br />
※以下的語法均為command令命，並在192.168.30.1的dns次要主機上執行<br />
(1)、新增Zone並宣告192.168.10.1為DNS紀錄來源</span></p>
<pre>dnscmd /zoneadd abc.com.tw /secondary 192.168.10.1</pre>
<p><span style="font-family: verdana, geneva;">(2)、指定上游解析來源</span></p>
<pre>dnscmd /resetforwarders 192.168.10.1 168.95.1.1 8.8.8.8</pre>
<p><span style="font-family: verdana, geneva;">※這裡多了168.95.1.1及8.8.8.8，是為了避免主要DNS失聯時導致完全無法解析的狀況。<br />
</span></p>
<p><span style="font-family: verdana, geneva;">(3)、設定不紀錄DNS告警事件</span></p>
<pre>dnscmd /config /eventloglevel 0</pre>
<p>※該設定為選項設定，請自行斟酌實際狀況需求</p>
<p><span style="font-family: verdana, geneva;">(4)、強制同步紀錄</span></p>
<pre>dnscmd /zonerefresh abc.com.tw</pre>
<p><span style="font-family: verdana, geneva;">4、補充說明<br />
</span><span style="font-family: verdana, geneva;">(1)、清除快取紀錄</span></p>
<pre>dnscmd /clearcache</pre>
<p><span style="font-family: verdana, geneva;">(2)、重新啟動DNS服務</span></p>
<pre>net stop dns &amp; net start dns</pre>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>常見的DNS套件BIND發布了數個漏洞，資安管理人員快手刀更新!!</title>
		<link>https://ailog.tw/lifelog/2022/09/24/bind-202209/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sat, 24 Sep 2022 05:45:19 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[BIND]]></category>
		<category><![CDATA[cve-2022-2795]]></category>
		<category><![CDATA[cve-2022-2881]]></category>
		<category><![CDATA[cve-2022-2906]]></category>
		<category><![CDATA[cve-2022-3080]]></category>
		<category><![CDATA[cve-2022-38177]]></category>
		<category><![CDATA[cve-2022-38178]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[named]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=13721</guid>

					<description><![CDATA[透過BIND套件架設DNS是業界很普遍的作法，近期Internet Systems Consortium(IS &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2022/09/24/bind-202209/" class="more-link">閱讀全文<span class="screen-reader-text">〈常見的DNS套件BIND發布了數個漏洞，資安管理人員快手刀更新!!〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-family: verdana, geneva; font-size: 14pt;">透過BIND套件架設DNS是業界很普遍的作法，近期Internet Systems Consortium(ISC)官網發佈了多個有關bind套件的漏洞，DNS服務在企業是一個相當關鍵角色，且需要高度資安防護的部份，資安管理人員快手刀更新套件吧。<span id="more-13721"></span></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">ISC發布多個bind相關漏洞套件：</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><a href="https://kb.isc.org/docs/cve-2022-2795">https://kb.isc.org/docs/cve-2022-2795</a></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><a href="https://kb.isc.org/docs/cve-2022-2881">https://kb.isc.org/docs/cve-2022-2881</a></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><a href="https://kb.isc.org/docs/cve-2022-2906">https://kb.isc.org/docs/cve-2022-2906</a></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><a href="https://kb.isc.org/docs/cve-2022-3080">https://kb.isc.org/docs/cve-2022-3080</a></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><a href="https://kb.isc.org/docs/cve-2022-38177">https://kb.isc.org/docs/cve-2022-38177</a></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><a href="https://kb.isc.org/docs/cve-2022-38178">https://kb.isc.org/docs/cve-2022-38178</a></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">受影響的bind版本範圍：</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">BIND 9.0.0 至 9.16.32</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">BIND 9.18.0 至 9.18.6</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">BIND 9.19.0 至 9.19.4</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">BIND 9.9.3-S1 至 9.11.37-S1</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">BIND 9.16.8-S1 至 9.16.32-S1</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">官方建議更新版本：</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">BIND 9.16.33 (Current Stable)</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">BIND 9.18.7 (Current Stable)</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">BIND 9.19.5 (Development)</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">BIND 9.16.33-S1 (Supported Preview Edition)</span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Azure雲端上的Ubuntu 18.04由於安全更新後導致DNS異常事件</title>
		<link>https://ailog.tw/lifelog/2022/08/31/azure-ubuntu18-dns/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Wed, 31 Aug 2022 07:16:46 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Azure]]></category>
		<category><![CDATA[CVE-2022-2526]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[systemd 237-3ubuntu10.54]]></category>
		<category><![CDATA[Ubuntu 18.04]]></category>
		<category><![CDATA[無法解析]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=13413</guid>

					<description><![CDATA[小編昨日就接到不少反映，放在Azure雲端上的服務突然異常，一開始心想應該是客戶手癢亂改了啥東西，但隨著反映越 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2022/08/31/azure-ubuntu18-dns/" class="more-link">閱讀全文<span class="screen-reader-text">〈Azure雲端上的Ubuntu 18.04由於安全更新後導致DNS異常事件〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-family: verdana, geneva; font-size: 14pt;">小編昨日就接到不少反映，放在Azure雲端上的服務突然異常，一開始心想應該是客戶手癢亂改了啥東西，但隨著反映越來越多人，真是不妙!</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">而且狀況均是DNS解析異常，且重新開機也無法改善，最終只能手動重新設定DNS相關資訊。<span id="more-13413"></span></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">官方事件說明：</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><a href="https://status.azure.com/zh-tw/status#">https://status.azure.com/zh-tw/status#</a></span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><img decoding="async" class="alignnone wp-image-13415 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/azure-ubuntu18-dns-01.png" alt="" width="1192" height="861" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/azure-ubuntu18-dns-01.png 1192w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/azure-ubuntu18-dns-01-300x217.png 300w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/azure-ubuntu18-dns-01-1024x740.png 1024w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/azure-ubuntu18-dns-01-768x555.png 768w" sizes="(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">事件起因：</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">Azure運行Ubuntu 18.04的虛擬機，於2022年8月30日大約17:00~1800左右自動進行了systemd 237-3ubuntu10.54 安全更新，該更新是為了解決CVE-2022-2526漏洞，但是該修補程式會導致Ubuntu 18.04上的DNS設定異常，如果有遇到該狀況則需要重新手動設定DNS。</span></p>
<p><span style="font-family: verdana, geneva; font-size: 14pt;">如何設定Ubuntu 18.04的DNS：</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;">vi /etc/systemd/resolved.conf</span><br />
<span style="font-family: verdana, geneva; font-size: 14pt;"><img decoding="async" class="alignnone wp-image-13416 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2022/08/azure-ubuntu18-dns-02.png" alt="" width="326" height="185" srcset="https://ailog.tw/lifelog/wp-content/uploads/2022/08/azure-ubuntu18-dns-02.png 326w, https://ailog.tw/lifelog/wp-content/uploads/2022/08/azure-ubuntu18-dns-02-300x170.png 300w" sizes="(max-width: 326px) 100vw, 326px" /></span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Bind服務被弱點掃描檢測出「DNS Server Cache Snooping Remote Information Disclosure」如何改善</title>
		<link>https://ailog.tw/lifelog/2021/09/28/allow-query-cache/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Tue, 28 Sep 2021 07:24:05 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[FreeBSD]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[BIND]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[DNS Server Cache Snooping Remote Information Disclosure]]></category>
		<category><![CDATA[freebsd]]></category>
		<category><![CDATA[named]]></category>
		<category><![CDATA[Nessus Plugin ID 12217]]></category>
		<category><![CDATA[弱點掃描]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=11207</guid>

					<description><![CDATA[透過Linux/FreeBSD主機架設DNS Server不意外都是採用BIND套件，但如果弱點掃描偵測出「D &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/09/28/allow-query-cache/" class="more-link">閱讀全文<span class="screen-reader-text">〈Bind服務被弱點掃描檢測出「DNS Server Cache Snooping Remote Information Disclosure」如何改善〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 14pt; font-family: verdana, geneva;">透過Linux/FreeBSD主機架設DNS Server不意外都是採用BIND套件，但如果弱點掃描偵測出「DNS Server Cache Snooping Remote Information Disclosure」相關的風險，該如何排除呢?<br />
小編今天分享一下處理的過程。<span id="more-11207"></span></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">弱點掃描影響說明：</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><a href="https://www.tenable.com/plugins/nessus/12217">https://www.tenable.com/plugins/nessus/12217</a><br />
</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">[範例情境]</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">01、作業系統為FreeBSD 12.2-RELEASE-p7</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">02、BIND版本為9.16.16</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">[操作步驟]</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">01、變更BIND設定檔<br />
(1)、編輯設定檔</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">指令語法：</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><span style="font-family: verdana, geneva;">vi /usr/local/etc/namedb/named.conf<br />
<img loading="lazy" decoding="async" class="alignnone wp-image-11209 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/09/allow-query-cache-01.png" alt="" width="713" height="86" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/09/allow-query-cache-01.png 713w, https://ailog.tw/lifelog/wp-content/uploads/2021/09/allow-query-cache-01-300x36.png 300w" sizes="auto, (max-width: 713px) 100vw, 713px" /></span></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">(2)、修改設定參數</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">在options選項裡面新增下列設定值<br />
options {</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">allow-query-cache { none; };</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">};</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone wp-image-11210 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/09/allow-query-cache-02.png" alt="" width="567" height="248" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/09/allow-query-cache-02.png 567w, https://ailog.tw/lifelog/wp-content/uploads/2021/09/allow-query-cache-02-300x131.png 300w" sizes="auto, (max-width: 567px) 100vw, 567px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">02、重新啟動BIND服務<br />
指令語法：<br />
/usr/local/etc/rc.d/named restart</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone wp-image-11211 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/09/allow-query-cache-03.png" alt="" width="687" height="114" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/09/allow-query-cache-03.png 687w, https://ailog.tw/lifelog/wp-content/uploads/2021/09/allow-query-cache-03-300x50.png 300w" sizes="auto, (max-width: 687px) 100vw, 687px" /></span><span style="font-size: 14pt; font-family: verdana, geneva;"><br />
</span></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>快更新!!! ISC BIND DNS軟體被發現多個高風險漏洞</title>
		<link>https://ailog.tw/lifelog/2021/05/23/isc-bind/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Sun, 23 May 2021 06:39:35 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[BIND]]></category>
		<category><![CDATA[CVE-2021-25214]]></category>
		<category><![CDATA[CVE-2021-25215]]></category>
		<category><![CDATA[CVE-2021-25216]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[ISC]]></category>
		<category><![CDATA[快更新!!! ISC BIND DNS軟體被發現多個高風險漏洞]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=8437</guid>

					<description><![CDATA[ISC發行的BIND DNS軟體，被發現了多個高風險漏洞，攻擊者可利用這些漏洞，透過遠端於被攻擊主機觸發阻斷服 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/05/23/isc-bind/" class="more-link">閱讀全文<span class="screen-reader-text">〈快更新!!! ISC BIND DNS軟體被發現多個高風險漏洞〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 14pt; font-family: verdana, geneva;">ISC發行的BIND DNS軟體，被發現了多個高風險漏洞，攻擊者可利用這些漏洞，透過遠端於被攻擊主機觸發阻斷服務狀況及遠端執行任意程式碼，伺服器管理者應盡快更新DNS主機BIND版本，避免遭受攻擊。<span id="more-8437"></span></span></p>
<p><span style="font-family: verdana, geneva;"><strong><span style="font-size: 14pt;">被發現的漏洞：</span></strong></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25214">CVE-2021-25214</a></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25215">CVE-2021-25215</a></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25216">CVE-2021-25216</a></span></p>
<p><span style="font-family: verdana, geneva;"><strong><span style="font-size: 14pt;">相關風險：</span></strong></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(1)、阻斷服務</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(2)、遠端執行程式碼</span></p>
<p><span style="font-family: verdana, geneva;"><strong><span style="font-size: 14pt;">受影響的BIND版本：</span></strong></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(1)、9.0.0 ~ 9.11.29</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(2)、9.12.0 ~ 9.16.13</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(3)、BIND 9.17 development branch 的 9.17.0 ~ 9.17.11</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(4)、9.9.3-S1 ~ 9.11.29-S1</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(5)、BIND Supported Preview Edition 的 9.16.8-S1 ~ 9.16.13-S1</span></p>
<p><span style="font-family: verdana, geneva;"><strong><span style="font-size: 14pt;">解決方法：</span></strong></span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">更新至以下版本或更高的版本</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(1)、BIND 9.11.31</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(2)、BIND 9.16.15</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(3)、BIND 9.17.12</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(4)、BIND 9.11.31-S1</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(5)、BIND 9.16.15-S1</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">ISC原廠說明：</span><br />
<span style="font-family: verdana, geneva;"><a href="https://kb.isc.org/docs/cve-2021-25214"><span style="font-size: 14pt;">https://kb.isc.org/docs/cve-2021-25214</span></a></span><br />
<span style="font-family: verdana, geneva;"><a href="https://kb.isc.org/docs/cve-2021-25215"><span style="font-size: 14pt;">https://kb.isc.org/docs/cve-2021-25215</span></a></span><br />
<span style="font-family: verdana, geneva;"><a href="https://kb.isc.org/docs/cve-2021-25216"><span style="font-size: 14pt;">https://kb.isc.org/docs/cve-2021-25216</span></a></span></p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>TFTP Server韌體更新、設定檔備份的好夥伴tftpd32!</title>
		<link>https://ailog.tw/lifelog/2020/04/21/tftpd32/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Tue, 21 Apr 2020 14:38:25 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[DHCP]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[ipv6]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[SNTP]]></category>
		<category><![CDATA[Syslog]]></category>
		<category><![CDATA[TFTP]]></category>
		<category><![CDATA[TFTP Server韌體更新]]></category>
		<category><![CDATA[TFTP Server韌體更新設定檔備份的好夥伴tftpd32!]]></category>
		<category><![CDATA[tftpd32]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=3285</guid>

					<description><![CDATA[維護網路設備時難免會遇到要「設定備份」或「軟體更新」的時候，雖然現在的設備都已相當流行透過網頁進行這些動作，但 &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2020/04/21/tftpd32/" class="more-link">閱讀全文<span class="screen-reader-text">〈TFTP Server韌體更新、設定檔備份的好夥伴tftpd32!〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p>維護網路設備時難免會遇到要「設定備份」或「軟體更新」的時候，雖然現在的設備都已相當流行透過網頁進行這些動作，但透過指令模式搭配TFTP Server來進行，整個操作過程不僅更加的快速，也相當適合大量設備維護時使用，就快跟著小編來了解如何使用免費版本的tftpd32吧!<span id="more-3285"></span></p>
<p>1、TFTP簡介<br />
TFTP(Trivial File Transfer Protocol)是一種很像FTP服務的協定，但不具有身分認證功能，且採用UDP 69埠為協定通訊埠，可以讓Client端上傳或下載檔案，最常被用來進行設備的設定檔備份或軟體更新等應用。</p>
<p>2、免費版的TFTP Server軟體<br />
tftpd32是一套20多年的opensource 軟體，從4.00版本開始支援IPV6，除了TFTP相關功能外，更包含了DHCP、DNS、SNTP、Syslog等功能，是一套相當出色的軟體。</p>
<p>tftpd32官方網址：<br />
<a href="https://tftpd32.jounin.net/">https://tftpd32.jounin.net/</a></p>
<p>下載頁面：<br />
<a href="https://tftpd32.jounin.net/tftpd32_download.html">https://tftpd32.jounin.net/tftpd32_download.html</a></p>
<p>注意事項：<br />
32位元最新版本為：v4.52<br />
64位元最新版本為：v4.64<br />
portable edition：為免安裝版本<br />
service edition：為安裝成伺服器服務的版本</p>
<p>3、tftpd32使用介紹<br />
(a)、程式檔案列表<br />
小編慣用的是免安裝版本，下圖為v4.64<br />
版本下載解壓縮後的檔案列表，其中tftpd64.exe則為主程式。<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-3313" src="https://ailog.tw/lifelog/wp-content/uploads/2020/04/TFTP001.png" alt="" width="200" height="132" /></p>
<p>(b)、軟體介面<br />
執行 tftpd64.exe 檔案後即可看到下圖的軟體介面。<br />
點選「Settings」進行軟體設定。<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-3315" src="https://ailog.tw/lifelog/wp-content/uploads/2020/04/TFTP002.png" alt="" width="405" height="341" srcset="https://ailog.tw/lifelog/wp-content/uploads/2020/04/TFTP002.png 405w, https://ailog.tw/lifelog/wp-content/uploads/2020/04/TFTP002-300x253.png 300w" sizes="auto, (max-width: 405px) 100vw, 405px" /><br />
Current Directory：為Tftp Server目前提供檔案傳輸的目錄，該目錄位置可以透過可以透過後方的「Browse」進行變更。<br />
Server interface：為目前提供Tftp服務的網路介面卡IP。<br />
點選「Show Dir」可以瀏覽目前目錄下有哪些檔案。</p>
<p>(c)、軟體功能項目設定<br />
在「GLOBAL」全區設定畫面可以挑選要啟用的服務項目，小編通常都作為tftp server來傳輸檔案，因此只勾選TFTP Server。<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-3317" src="https://ailog.tw/lifelog/wp-content/uploads/2020/04/TFTP003.png" alt="" width="400" height="564" srcset="https://ailog.tw/lifelog/wp-content/uploads/2020/04/TFTP003.png 400w, https://ailog.tw/lifelog/wp-content/uploads/2020/04/TFTP003-213x300.png 213w" sizes="auto, (max-width: 400px) 100vw, 400px" /></p>
<p>(d)、TFTP服務目錄設定<br />
接著在TFTP頁面設定「Base Directory」目錄，將路徑設定在想要進行檔案傳輸的目錄。(例如韌體下載、設定檔下載等)<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-3319" src="https://ailog.tw/lifelog/wp-content/uploads/2020/04/TFTP004.png" alt="" width="400" height="564" srcset="https://ailog.tw/lifelog/wp-content/uploads/2020/04/TFTP004.png 400w, https://ailog.tw/lifelog/wp-content/uploads/2020/04/TFTP004-213x300.png 213w" sizes="auto, (max-width: 400px) 100vw, 400px" /></p>
<p>(e)、TFTP目錄確認<br />
回到主畫面後點選「Show Dir」確認一下檔案列表中是否為想要傳輸的檔案，如果沒問題就可以開始透過TFTP Server服務來上傳或下傳檔案，但路徑如有錯誤請重新選擇正確的目錄。<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-3320" src="https://ailog.tw/lifelog/wp-content/uploads/2020/04/TFTP005.png" alt="" width="408" height="342" srcset="https://ailog.tw/lifelog/wp-content/uploads/2020/04/TFTP005.png 408w, https://ailog.tw/lifelog/wp-content/uploads/2020/04/TFTP005-300x251.png 300w" sizes="auto, (max-width: 408px) 100vw, 408px" /></p>
<p>(f)、點選「Log viewer」可以查看傳輸紀錄<br />
<img loading="lazy" decoding="async" class="alignnone size-full wp-image-3323" src="https://ailog.tw/lifelog/wp-content/uploads/2020/04/TFTP006.png" alt="" width="405" height="341" srcset="https://ailog.tw/lifelog/wp-content/uploads/2020/04/TFTP006.png 405w, https://ailog.tw/lifelog/wp-content/uploads/2020/04/TFTP006-300x253.png 300w" sizes="auto, (max-width: 405px) 100vw, 405px" /></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
