Threats to DNS Servers

Because Windows 2000 and Windows Server 2003 depend on the DNS name service, DNS servers are targets for attacks. Attackers can pose the following threats to the DNS service:

  • Overwriting of existing DNS resource records and hijacking sessions

  • Acquisition of DNS zone data by performing unauthorized zone transfers

  • Exposure of the internal IP addressing scheme to the public network

  • Denial-of-service attacks that disable all DNS services

  • Preventing access to the forest root domain’s DNS resource records

Modification of DNS Records

By supporting dynamic DNS updates, a Windows 2000 or Windows Server 2003 DNS server is susceptible to modification of DNS resource records if the security of the DNS server is not configured correctly. ...

Get Microsoft® Windows® Security Resource Kit, Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.