[Pdns-users] Supermasters and permissions

Benny Amorsen benny+pdns at amorsen.dk
Wed Oct 22 09:21:31 UTC 2003

On 2003-10-22 at 03:29, Daniel Ceregatti wrote:

> Supermaster A creates a domain foo.com. Supermaster B, knowing foo.com
> is setup on the powerdns name server from another supermaster, does an
> AFXR of foo.com, thereby replacing the foo.com zone on the powerdns server.

AXFR's are initiated by the slave, not the master. All the master can do
is send a notify, possibly causing the slave to refetch the zone from
the usual master. Not much of an exploit there.


