STIGQter STIGQter: STIG Summary: Infoblox 8.x DNS Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The Infoblox DNS service member must not reveal sensitive information to an attacker. This includes Host Information (HINFO), Responsible Person (RP), Location (LOC) resource, and sensitive text string resource (TXT) record data.

DISA Rule

SV-233857r1082603_rule

Vulnerability Number

V-233857

Group Title

SRG-APP-000333-DNS-000107

Rule Version

IDNS-8X-200001

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Fix external DNS zone data and verify there are no HINFO, LOC, RP, or TXT RRs that disclose any information that can be used for malicious purposes.

1. Navigate to Data Management >> DNS >> Zones.
2. Select and edit the zone identified during the Check.
3. Select the RR, and click "Delete" to remove the record.

Changing the value of MNAME in the SOA record.

1. Navigate to Data Management >> DNS >> Zones.
2. Select and the external zone identified during the Check.
3. Select the SOA record and edit.
4. Change the value of primary name server (MNAME) to an arbitrary value.

Check Contents

Review external DNS zone data and verify there are no HINFO, LOC, RP, or TXT RRs that disclose any information that can be used for malicious purposes.

1. Navigate to Data Management >> DNS >> Zones tab.
2. Click on the appropriate DNS Zone.
3. Review external zone data for HINFO, LOC, RP, and TXT RRs.

If any HINFO, LOC, RP, or TXT RRs exist that disclose any information that may be used for malicious purposes, this is a finding.

Vulnerability Number

V-233857

Documentable

False

Rule Version

IDNS-8X-200001

Severity Override Guidance

Review external DNS zone data and verify there are no HINFO, LOC, RP, or TXT RRs that disclose any information that can be used for malicious purposes.

1. Navigate to Data Management >> DNS >> Zones tab.
2. Click on the appropriate DNS Zone.
3. Review external zone data for HINFO, LOC, RP, and TXT RRs.

If any HINFO, LOC, RP, or TXT RRs exist that disclose any information that may be used for malicious purposes, this is a finding.

Check Content Reference

M

Target Key

5251