4 - Validate Name Registration Security

Information

The Name Registration process is where you register your domain and name server so you are part of the DNS system. There are many authorized name registration providers available, and the security of your name registration depends on their process for authenticating registration change requests.

Rationale:

If an attacker can take control of your name registration, then there is no need for her to compromise, spoof or otherwise subvert your DNS services, when she can have all of the DNS requests redirected to the DNS servers of her choice. In the past, name registration changes could be easily spoofed by sending an e-mail from the proper address. These days most registrars have raised the bar somewhat by requiring a response via e-mail, or they require that an administrator log onto a web site with a password. Most registrars also have fallback processes in place for handling cases where the contact e-mail is not working. It is highly recommended that you check with your registrar and review the authentication process, including alternative authentication options. In the balance between ease of use and reliable authentication, most registrars seem to heavily favor the ease of use. Many registrars also provide stronger authentication controls which are not required by default, but that are available upon request. Also consider who is registering the domain. If an organization commissions a site through a third party it should ensure that the registration is assigned to someone within the organization, rather than the commissioned party.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Verify and document what security controls are in place for changes to your DNS registration and who is authorized to make changes. Also, regularly check the results of a whois query and verify that the information are correct.