Executive brief
A misconfiguration in certain DNS servers allows unauthorized users to request a full copy of a domain's records, known as a zone transfer. This allows an outsider to map out a company's internal network structure, including the names and addresses of private servers and devices. While this does not directly crash systems, it provides attackers with a roadmap for more targeted and damaging cyberattacks.
Technical details
The vulnerability arises from a DNS server being configured to respond to Asynchronous Transfer Full Range (AXFR) requests from any source rather than restricting them to authorized secondary servers. A remote, unauthenticated attacker can initiate a zone transfer to obtain a complete list of resource records for a DNS zone. This information disclosure reveals subdomains, IP addresses, and internal network topology, which facilitates reconnaissance for subsequent attacks. The issue is a configuration weakness (CWE-16) rather than a software bug. Mitigation involves configuring the DNS daemon (e.g., BIND) to restrict AXFR responses to specific, trusted IP addresses.
Affected products
- Generic DNS Server
Timeline
- 1997-07-01: disclosed: Initial NVD publication date
- 2015-04-13: advisory: CISA (US-CERT) issued an alert regarding ongoing exploitation and scanning for this misconfiguration.