But if MS DNS crashes just by sending a continuos stream of the ASCII set,
this can be easily done on a script, with no need to get it from the host
itself.
Workaround #1: block port tcp/53 on the security panel of TCP/IP. No more
zone transfers, no more TCP name resolutions (very rare), everyday UDP
resolution still works.
Workaround #2: filter port tcp/53 on the boundary router, allowing only
secondary servers to do zone transfers.
Workaround #3: install BIND.
Rubens Kuhl Jr.
----------
| $ telnet ntbox 19 | telnet ntbox 53
|
| Tested on NT 4.0 with service pack #3.
|
| Hello Dr. Watson, goodbye Mr. Nameserver.