This is a text-only version of the following page on https://raymii.org: --- Title : Hide or determine BIND version number Author : Remy van Elst Date : 08-05-2013 URL : https://raymii.org/s/tutorials/Get_DNS_server_version_and_hide_it_in_BIND.html Format : Markdown/HTML --- The BIND nameserver (and many others) return their version number when queried a special DNS query. This gives exposure and that is most of the time a bad thing. This tutorial shows you how to query DNS servers for their version and how to stop/change your own BIND server version exposure.

Recently I removed all Google Ads from this site due to their invasive tracking, as well as Google Analytics. Please, if you found this content useful, consider a small donation using any of the options below:

I'm developing an open source monitoring app called Leaf Node Monitoring, for windows, linux & android. Go check it out!

Consider sponsoring me on Github. It means the world to me if you show your appreciation and you'll help pay the server costs.

You can also sponsor me by getting a Digital Ocean VPS. With this referral link you'll get $100 credit for 60 days.

### Chaos Query The following `DIG` and `NSLOOKUP` queries will show the version of BIND: A home router queried with `DIG`: dig @192.168.1.1 version.bind txt chaos ;; ANSWER SECTION: version.bind. 0 CH TXT "dnsmasq-2.47" A Microsoft DNS server queried with `nslookup`: nslookup -type=txt -class=chaos version.bind ns1.metaregistrar.nl Server: ns1.metaregistrar.nl Address: 81.4.97.217#53 version.bind text = "Served by PowerDNS - http://www.powerdns.com" What is `chaos` or CH class you ask? [It is/was a network technology, see the wikipedia page for more info.][2]. There is also the [HS class, that stands for Hesiod.][3] ### Hide it in BIND When running a BIND nameserver, edit your `/etc/bind/named.conf.options` file (or the config file where you have your options) and add the following option: options { [...] version "Not supported"; } You can of course put whatever you like in there, for example you can spoof a Microsoft DNS server: version "Microsoft DNS 6.0.6100 (2AEF76E)"; Or like TransIP does, make it look like your own DNS software: dig @ns1.transip.nl version.bind txt chaos ;; ANSWER SECTION: version.bind. 86400 CH TXT "TransDNS 2.1.1" Make sure to reload/restart your BIND servers after the change. Do note that you need BIND 8.2 or later for this option to work. ### db.bind zone You can also add a .bind zone, this way your queries will also be logged and you can block possible attempts. `/etc/bind/named.conf.local`: view "chaos" CH { match-clients { any; }; zone "bind" CH { type master; file "db.bind"; allow-update { none; }; }; }; `/etc/bind/db.bind`: $TTL 3600 @ 86400 CH SOA localhost. root.localhost. ( 2013050801 ; serial 3600 ; refresh 3600 ; retry 604800 ; expiry 86400 ) ; minimum ; @ CH NS localhost. version CH TXT "Microsoft DNS 6.0.6100 (2AEF76E)" authors CH TXT "Raymii.org" However this gets complicated very fast, you need to wrap all your other zones in views as well: view "default" IN { match-clients { any; }; [...] }; So it's better to use the above options file. [1]: https://www.digitalocean.com/?refcode=7435ae6b8212 [2]: https://en.wikipedia.org/wiki/Chaosnet [3]: https://en.wikipedia.org/wiki/Hesiod_(name_service) --- License: All the text on this website is free as in freedom unless stated otherwise. This means you can use it in any way you want, you can copy it, change it the way you like and republish it, as long as you release the (modified) content under the same license to give others the same freedoms you've got and place my name and a link to this site with the article as source. This site uses Google Analytics for statistics and Google Adwords for advertisements. You are tracked and Google knows everything about you. Use an adblocker like ublock-origin if you don't want it. All the code on this website is licensed under the GNU GPL v3 license unless already licensed under a license which does not allows this form of licensing or if another license is stated on that page / in that software: This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this program. If not, see . Just to be clear, the information on this website is for meant for educational purposes and you use it at your own risk. I do not take responsibility if you screw something up. Use common sense, do not 'rm -rf /' as root for example. If you have any questions then do not hesitate to contact me. See https://raymii.org/s/static/About.html for details.