EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesMedium
A security team is reviewing its public-facing DNS infrastructure for potential enumeration vulnerabilities. They discover that their primary DNS server is configured to allow any external host to perform a full zone transfer. Which countermeasure should be implemented immediately to prevent unauthorized disclosure of internal network topology and host information?
- ADeploy a Web Application Firewall (WAF) in front of the DNS server.
- BImplement DNSSEC on all DNS zones.
- CChange the default port for DNS queries from UDP 53 to a custom port.
- DConfigure the DNS server to only allow zone transfers to authorized secondary DNS servers.
Show answer & explanationAnswer & explanation
Correct answer: D. Configure the DNS server to only allow zone transfers to authorized secondary DNS servers.
Allowing full zone transfers to 'any external host' is a critical misconfiguration that directly leads to DNS enumeration. The most effective countermeasure is to restrict zone transfers to only specifically authorized secondary DNS servers, often using an Access Control List (ACL).
Why the other options are wrong
- A. A WAF protects web applications, not DNS servers, from attacks.
- B. DNSSEC provides authentication and integrity for DNS data but does not directly prevent unauthorized zone transfers.
- C. Changing the default DNS port is security through obscurity and would break legitimate DNS resolution for external clients.
DNS Zone Transfer Countermeasure
Measures taken to prevent unauthorized disclosure of DNS zone data through zone transfers, typically by restricting which hosts can perform them.
- Zone transfers disclose network topology
- Restrict to authorized secondary DNS servers only
- Implement Access Control Lists (ACLs)
Memory trick: Restrict the transfer to trusted friends only, not strangers.