UCF STIG Viewer Logo

The DNS implementation must restrict error messages so only authorized personnel may view them.


Overview

Finding ID Version Rule ID IA Controls Severity
V-34271 SRG-NET-000313-DNS-000174 SV-44750r1_rule Medium
Description
If the application provides too much information in error logs and administrative messages to the screen, this could lead to compromise if the information is available to non authorized personnel. If controls are not in place to protect the error message, an attacker could use the information to his/her advantage and compromise the system based on what is known about the error. The structure and content of error messages need to be carefully considered by the organization and development team. The extent to which the information system is able to identify and handle error conditions is guided by organizational policy and operational requirements.
STIG Date
Domain Name System (DNS) Security Requirements Guide 2012-10-24

Details

Check Text ( C-42255r1_chk )
Review the DNS configuration to determine if controls are in place to restrict error messages, so only authorized personnel may view them. If controls are not in place to restrict access to the error messages, this is a finding.
Fix Text (F-38202r1_fix)
Configure the DNS implementation to restrict error messages, so only authorized personnel may view them.