DNS_SPOOF query response PTR with TTL of 1 min. and no authority

 

Code: p420

Severity: Warning

 

Description: This event is generated when a specific DNS response. In this case, there are no DNS authority records for the queried pointer record and has a DNS time-to-live value of one minute.

Impact: Ranges from harmless to severe. A successful corrupted DNS IP and name pairing can range from harmless (if the IP is not used) to severe (if a user is misdirected to a hostile host).

Corrective: Consider using DNSSEC where appropriate.