|
|
|
|
|
|
|
| |
DNS Server Zone Tranfer Information Disclosure (AXFR) |
|
| This script is Copyright (C) 2000-2010 j_lampe@bellsouth.net |
|
|
| Family | DNS |
| Nessus Plugin ID | 10595 (dns_xfer.nasl) |
| Bugtraq ID |
|
| CVE ID | CVE-1999-0532
|
|
| Description: |
Synopsis :
The remote name server allows zone transfers
Description :
The remote name server allows DNS zone transfers to be performed.
A zone transfer lets a remote attacker instantly populate a list of
potential targets. In addition, companies often use a naming
convention that can give hints as to a servers primary application
(for instance, proxy.example.com, payroll.example.com,
b2b.example.com, etc.).
As such, this information is of great use to an attacker, who may use
it to gain information about the topology of the network and spot new
targets.
See also :
http://en.wikipedia.org/wiki/AXFR
Solution :
Limit DNS zone transfers to only the servers that need the
information.
Risk factor :
Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
|
|
|
|
|
|