STIGQter STIGQter: STIG Summary: Microsoft Windows 2012 Server Domain Name System Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 23 Apr 2021:

The DNS Name Server software must be configured to refuse queries for its version information.

DISA Rule

SV-215640r561297_rule

Vulnerability Number

V-215640

Group Title

SRG-APP-000333-DNS-000104

Rule Version

WDNS-SI-000003

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To disable the version being returned in queries, execute the following command:

dnscmd /config /EnableVersionQuery 0 <enter>

Check Contents

The "EnableVersionQuery" property controls what version information the DNS server will respond with when a DNS query with class set to “CHAOS” and type set to “TXT” is received.

Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.

Open a command window and execute the command:

nslookup <enter>
Note: Confirm the Default Server is the DNS Server on which the command is being run.

At the nslookup prompt, type:

set type=TXT <enter>
set class=CHAOS <enter>
version.bind <enter>

If the response returns something similar to text = "Microsoft DNS 6.1.7601 (1DB14556)", this is a finding.

Vulnerability Number

V-215640

Documentable

False

Rule Version

WDNS-SI-000003

Severity Override Guidance

The "EnableVersionQuery" property controls what version information the DNS server will respond with when a DNS query with class set to “CHAOS” and type set to “TXT” is received.

Log on to the DNS server using the Domain Admin or Enterprise Admin account or Local Administrator account.

Open a command window and execute the command:

nslookup <enter>
Note: Confirm the Default Server is the DNS Server on which the command is being run.

At the nslookup prompt, type:

set type=TXT <enter>
set class=CHAOS <enter>
version.bind <enter>

If the response returns something similar to text = "Microsoft DNS 6.1.7601 (1DB14556)", this is a finding.

Check Content Reference

M

Target Key

4016

Comments