Author: Great Lakes
Date: 16-09-03 14:45
the ls -d zone file listing is only allowed if zone transfers are allowed. To further restrict this time of informaiton leaking out, TCP port 53 can be filtered from all but trsuted DNS secondaries. ls -d's run against a domain will result in a server timeout, confounding anyone attempting to get a full listing of all the machines in your network. Leaving UDP 53 open will still allow individual queries for hostname resolution.
|
|