Junglewise Threat Intelligence

CVE-1999-0533: Generic DNS server information disclosure via inverse queries

CVE-1999-0533 · Severity: high · CVSS 7.5 · Published 1997-07-01

Technologies: Generic DNS Server. Vendors: Generic.

Executive brief

A configuration issue in certain Domain Name System (DNS) servers allows them to process inverse queries, which are requests to find a domain name based on an IP address. This capability can be abused by attackers to map out internal network structures or gather sensitive information about organizational assets. Such reconnaissance often serves as a precursor to more targeted attacks against company infrastructure.

Technical details

The vulnerability involves a DNS server that has inverse query (IQUERY) support enabled. Inverse queries allow a requester to provide a resource record and ask for the associated domain name, a feature that was deprecated due to its inefficiency and security implications. An unauthenticated remote attacker can use this feature to perform network mapping and reconnaissance. By querying the DNS server in this manner, an attacker can potentially discover hostnames and internal IP address schemes. Most modern DNS implementations have disabled or removed support for IQUERY to mitigate this risk.

Affected products

  • Generic DNS Server

Timeline

  • 1997-07-01: disclosed: NVD Published Date

References

Related threats