More Info:

Ensure Subdomain NS Records are not Vulnerable

Risk Level

High

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the vulnerability of AWS Subdomain NS Records in AWS Route53 using the AWS console, follow these steps:

  1. Log in to the AWS Management Console.
  2. Open the Route53 service.
  3. In the navigation pane, select “Hosted zones”.
  4. Choose the hosted zone that contains the vulnerable subdomain NS records.
  5. Select the checkbox next to the vulnerable subdomain NS record(s) that you want to remediate.
  6. Click on the “Delete record set” button at the top of the page.
  7. Confirm the deletion by clicking on the “Delete” button in the pop-up window.
  8. Repeat steps 5-7 for all the vulnerable subdomain NS records.
  9. Once the vulnerable subdomain NS records are deleted, click on the “Create record set” button at the top of the page.
  10. In the “Name” field, enter the name of the subdomain for which you want to create NS records.
  11. Select “NS - Name Server” from the “Type” dropdown menu.
  12. In the “Value” field, enter the name servers (NS records) provided by your DNS hosting provider.
  13. Click on the “Create” button to create the new NS records.
  14. Repeat steps 10-13 for each subdomain that requires NS records.
  15. Once all the necessary NS records are created, verify that the subdomain NS records are no longer vulnerable by performing a vulnerability scan or using a DNS tool.

By following these steps, you will be able to remediate the vulnerability of AWS Subdomain NS Records in AWS Route53 using the AWS console.