EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesMedium
A security team is implementing countermeasures against footprinting. They are particularly concerned about sensitive internal IP address ranges and hostnames being discovered through public DNS records. Which of the following is the most effective countermeasure to prevent this specific type of information leakage?
- AImplementing robust firewall rules to block all incoming ICMP traffic.
- BEncrypting all internal network traffic with IPSec.
- CDisabling DNS zone transfers on external-facing DNS servers.
- DRegularly changing public IP addresses to confuse attackers.
Show answer & explanationAnswer & explanation
Correct answer: C. Disabling DNS zone transfers on external-facing DNS servers.
Disabling DNS zone transfers on external-facing DNS servers is a critical countermeasure. If allowed, an attacker could request and obtain a full list of all DNS records for a domain, revealing internal IP ranges and hostnames. Restricting this prevents a significant footprinting vector.
Why the other options are wrong
- A. Blocking ICMP traffic prevents some host discovery but doesn't stop information leakage from DNS records.
- B. Encrypting internal network traffic protects data in transit but doesn't prevent public DNS records from being queried.
- D. Regularly changing public IP addresses is impractical, disruptive, and doesn't prevent the leakage of internal hostnames or IP ranges from existing DNS records.
DNS Zone Transfer Countermeasures
Countermeasures against DNS zone transfers primarily involve configuring DNS servers to restrict zone transfer requests only to authorized secondary DNS servers, preventing unauthorized access to full domain record lists.
- Zone transfers are typically restricted by IP address.
- Essential for preventing comprehensive network mapping by attackers.
- Applies to both primary and secondary DNS servers.
- Often overlooked, leading to significant information disclosure.
Memory trick: Hide your footprints, especially the DNS map to your house.