I've bind 9.3.6.
How can I disable hostname disclosure ?
Issue link http://www.iss.net/security_center/reference/vuln/bind-hostname-disclosure.htm
Thanks.
I've bind 9.3.6.
How can I disable hostname disclosure ?
Issue link http://www.iss.net/security_center/reference/vuln/bind-hostname-disclosure.htm
Thanks.
"There is no remedy as of December 18, 2010." Wrong, so very wrong. There has been a fix since February 2006 (at least). Put this in your BIND config (it probably is there already):
Let me "craft" this "special" query (don't attempt this at home):
For more info on securing BIND have a look at http://www.cymru.com/Documents/secure-bind-template.html
You can hide hostname and version this way:
Hostname querying example:
You can disable hostname.bind by putting this in named.conf (valid in BIND 9.9 that I use):