DNS Security & Cache Poisoning Defense
Intermediate75 min5 objectives

DNS Security & Cache Poisoning Defense

Practice DNS Security & Cache Poisoning Defense by producing and reviewing portable evidence without requiring unavailable host, cloud, hardware, or multi-node access.

Briefing

### Scenario You are a dns practitioner handling a realistic client engagement. For DNS Security & Cache Poisoning Defense, the client has provided a staging environment that mirrors production but is isolated to this lab. Your task is to demonstrate the core technique on the local target without touching external systems. The scenario is intentionally scoped to what you can verify inside the container. ### Environment and scope Use the Ubuntu 22.04 practice container. Working directory is `/home/student/lab-work` (create it with `mkdir -p`). Target is `127.0.0.1` and `127.0.0.1:8080` where a `python3 -m http.server` or service-specific daemon runs. Install only needed tools via `sudo apt-get update && sudo apt-get install -y bind9, dnsutils` then verify with `named -v (9.18.39) && dig -v`. Credentials: `student:lab123` with `sudo` (created via `useradd` + `chpasswd` + `sudoers.d` as in `labs.service.ts:554`). Do not scan or query outside 127.0.0.0/8 or lab-work. Scope is strictly container-only; no external cloud, hardware, or nested container engines. ### Mission objective For DNS Security & Cache Poisoning Defense: install and verify tooling, prepare the local target (`bind9 on 127.0.0.1 with lab.internal zone`), execute the technique step-by-step, and collect evidence. Each walkthrough step produces a verifiable artifact (file, command output, or service state) that you will cite in your submission. ### Success criteria You have completed the lab when: - Tooling verification passes (`named -v (9.18.39) && dig -v` returns expected version without error) - Local target is running and responds (`curl -s http://127.0.0.1:8080/` or `dig @127.0.0.1` or `tshark -r` shows expected output) - `solution.md` in `lab-work` documents each step's exact command, raw output excerpt, and your interpretation (what the output proves) - All flag answers are direct values from your local output (e.g., version string, status code, IP, header name) and no external hosts were targeted (`history | grep -E "nmap|dig|tshark|openssl|nikto|curl"` shows only 127.0.0.1) Runtime mode: portable artifact validation

Objectives

  • 1Prepare workspace and verify tooling
  • 2Prepare local target for DNS Security & Cache Poisoning Defense
  • 3Start BIND without systemd
  • 4Create and validate zone
  • 5Complete DNS Installer
  • 6Complete DNSSEC Enabler
  • 7Tune and interpret
  • 8Compile and verify submission

Flags

DNS Installer+100 pts

Submit the version string reported by the installed tool for DNS Installer (e.g., check with --version or -v).

DNSSEC Enabler+250 pts

Submit the single keyword indicating success for DNSSEC Enabler (e.g., running, OK, enabled) from local tool output.

DNS Logger+150 pts

Submit the observed value for DNS Logger from local tool output on 127.0.0.1 (e.g., status code, header name, or count).

RRL Configurator+200 pts

Submit the single keyword indicating success for RRL Configurator (e.g., running, OK, enabled) from local tool output.

Zone Crafter+200 pts

Submit the synthesized artifact value for Zone Crafter (e.g., IP 127.0.0.2 or zone name) as verified by dig or cat /etc/bind/.