B
Brad Baker
A security scan of one of our windows DNS servers revealted the following
potential problem:
The remote name server allows DNS zone transfers to be performed. This
information is of great use to an attacker who may use it to gain
information about the topology of your network and spot new targets.
Solution: Restrict DNS zone transfers to only the servers that absolutely
need it. Risk Factor: Medium CVE: CAN-1999-0532
I've found information online on how to restrict zone transfers on a zone by
zone basis. My problem is that I have a DNS server with approximately 300+
zones. I don't want to go into each zone manually and setup zone transfer
restrictions - that would take hours.
I also found that there is a command line utility (dnscmd) which can be
used, and while that would be slightly more practical than using the GUI its
still pretty tedious to use to reset zone transfer information on 300+
zones.
There has to be a way to set zone transfer settings on a server wide basis?
What am I missing?
Thanks,
Brad
potential problem:
The remote name server allows DNS zone transfers to be performed. This
information is of great use to an attacker who may use it to gain
information about the topology of your network and spot new targets.
Solution: Restrict DNS zone transfers to only the servers that absolutely
need it. Risk Factor: Medium CVE: CAN-1999-0532
I've found information online on how to restrict zone transfers on a zone by
zone basis. My problem is that I have a DNS server with approximately 300+
zones. I don't want to go into each zone manually and setup zone transfer
restrictions - that would take hours.
I also found that there is a command line utility (dnscmd) which can be
used, and while that would be slightly more practical than using the GUI its
still pretty tedious to use to reset zone transfer information on 300+
zones.
There has to be a way to set zone transfer settings on a server wide basis?
What am I missing?
Thanks,
Brad