DNS predictable query |
---|
Risk Level: | Medium | Check or Attack Name: DNS Predictable Query |
---|---|---|
Platforms: | Windows NT, Windows NT: 4.0, Windows NT: 4.0 SP2, Windows NT: 4.0 SP1, Windows NT: 4.0 SP3 | |
Description: | An unpatched version of Windows NT DNS has been found. If the DNS query numbers are predictable, it is possible for an attacker to spoof replies to DNS queries, which could potentially redirect traffic to hostile sites. |
|
Remedy: | Apply the latest Windows NT 4.0 Service Pack or the post-SP3 dns-fix patch. To apply the latest Windows NT 4.0 Service Pack, follow these steps:
—OR— Windows NT 4.0 Service Pack 3 (SP3) users must apply the post-SP3 dns-fix patch available from ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/nt40/hotfixes-postSP3/dns-fix/. |
|
References: | Microsoft Knowledge Base Article Q167629, Predictable Query IDs Pose Security Risks for DNS Servers, http://support.microsoft.com/support/kb/articles/q167/6/29.asp Microsoft Knowledge Base Article Q167629, Predictable Query IDs Pose Security Risks for DNS Servers, ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/NT40/hotfixes-postSP3/dns-fix/Q167629.txt |
Know Your Risks |