Synopsis
The remote name server is misconfigured.
Description
The remote nameserver has dynamic updates enabled.
The dynamic updates let the BIND administrator update the name service information dynamically.
However, it is possible to trick BIND into changing the resource record for the zone it serves. An attacker may use this flaw to hijack the traffic going to the servers and redirect it to an arbitrary site.
Solution
If BIND is being used, add the option
allow-update {none;};
in the named.conf configuration file to disable this feature entirely.
Plugin Details
File Name: bind_allows_updates.nasl
Supported Sensors: Nessus
Vulnerability Information
CPE: cpe:/a:isc:bind
Required KB Items: DNS/udp/53