Bind is a security hole, period. If you run it, do so in a chroot jail. I'm a fan of TinyDNS (DJB), personally.
Besides that, there are ways for DNS servers to be modified other than changing the zone records directly. DNS allows servers to be setup as slaves to other servers, and they...