14 - Hide BIND Version String

Information

The version string contains the version of BIND that is running.

Rationale:

Additional information hiding or obscurity can be provided by preventing the version information being returned to TXT queries to the pseudo-domain 'version.bind' in the chaos class.

Solution

Place the following in the global options of named.conf:
options {
version 'None'; . . . }

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-30(5)

Plugin: Unix

Control ID: b693da61afd4be2d00f9255f404a9b3b961f2b64f3664eefea1ae0b6521a7492