More Info:

Ensure Azure Subdomain NS Records are not vulnerable

Risk Level

Medium

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the Azure Subdomain NS Records vulnerability in the Azure Network using the Azure console, follow these steps:

  1. Log in to the Azure portal (portal.azure.com) using your Azure account credentials.

  2. Navigate to the Azure DNS service by searching for “DNS” in the search bar at the top of the portal and selecting “DNS zones” from the results.

  3. In the DNS zones blade, select the DNS zone that contains the vulnerable subdomain NS records.

  4. Once you’ve selected the DNS zone, you will see a list of DNS records associated with it. Look for the NS records related to the vulnerable subdomain.

  5. Select the vulnerable NS record to open the record details.

  6. In the record details, click on the “Edit” button to modify the NS record.

  7. Replace the existing vulnerable NS record with the correct NS record provided by your DNS provider or the authoritative DNS server for the subdomain.

  8. Save the changes by clicking on the “Save” button.

  9. Repeat steps 5 to 8 for all the vulnerable NS records associated with the subdomain.

  10. Once you have updated all the NS records, monitor the DNS propagation to ensure the changes are reflected across the DNS infrastructure. This may take some time depending on the TTL (Time to Live) settings of the DNS records.

  11. After the DNS changes have propagated, verify the subdomain NS records using DNS lookup tools or commands to ensure they are pointing to the correct authoritative DNS servers.

By following these steps, you will be able to remediate the Azure Subdomain NS Records vulnerability in the Azure Network using the Azure console.