Network misconfigurations

Elastic Load Balancer (ELB) allows ingress access to DNS port 53

Platform(s)
Compliance Frameworks
  • CCPA
  • ,
  • Mitre ATT&CK
  • ,
  • New Zealand Information Security Manual
  • ,
  • NIST 800-171
  • ,
  • NIST 800-53
  • ,
  • Orca Best Practices
  • ,
  • UK Cyber Essentials

Description

DNS port - 53 is used to query Domain Names to IP address. Allowing inbound traffic from all external IP addresses to DNS port can be vulnerable to DNS Hijacking, Cache Poisoning, and DNS Tunnelling attack. It is a best practice to restrict access from known public DNS server to destination port 53.