DNS Server BIND version Directive Remote Version Detection

info Nessus Plugin ID 10028

Synopsis

It is possible to obtain the version number of the remote DNS server.

Description

The remote host is running BIND or another DNS server that reports its version number when it receives a special request for the text 'version.bind' in the domain 'chaos'.

This version is not necessarily accurate and could even be forged, as some DNS servers send the information based on a configuration file.

Solution

It is possible to hide the version number of BIND by using the 'version' directive in the 'options' section in named.conf.

Plugin Details

Severity: Info

ID: 10028

File Name: bind_version.nasl

Version: 1.61

Type: remote

Family: DNS

Published: 10/12/1999

Updated: 10/12/2022

Asset Inventory: true

Supported Sensors: Nessus

Vulnerability Information

CPE: cpe:/a:isc:bind

Required KB Items: dns_server/version

Reference Information

IAVT: 0001-T-0583