# Cis Bind9 V301 6 1

> Hide BIND Version String (Scored)

- Skill: `cyberstrikeus/cis-bind9-v301-6-1` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-bind9-v301-6-1`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-bind9-v301-6-1/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-bind9-v301-6-1

---


# CIS 6.1 — Hide BIND Version String

## Profile Applicability

- Level 1 - Authoritative Name Server
- Level 1 - Caching Only Name Server

## Description

BIND includes a built-in zone, `version.bind` which may be queried to get the version of the name server. The version may be set to a value of `none`, to disable reporting of the version information.

## Rationale

Making detailed BIND version information easy to obtain remotely helps attackers automate and target their attacks. The information is not necessary for the health of the server, and should not be disclosed.

## Impact

None noted.

## Audit Procedure

Use the dig command shown below to query the chaos class TXT record on `version.bind`. If there is no output from the command, or if a value of `No Info` or `None` is returned then the configuration is compliant.

```bash
$ dig @ns1.cisecurity.org version.bind chaos txt | grep '^version.bind.' | grep TXT
version.bind. 0 CH TXT "No Info"

$ dig @ns2.cisecurity.org version.bind chaos txt | grep '^version.bind.' | grep TXT
$
```

## Remediation

Add or modify the version option to have a value of `none` in the BIND global options, as shown below.

```
options {
version none;
. . .
}
```

## Default Value

Default value returns the current BIND detailed version.

## References

None listed.

## CIS Controls

| Controls Version | Control                                                              | IG 1 | IG 2 | IG 3 |
| ---------------- | -------------------------------------------------------------------- | ---- | ---- | ---- |
| v6               | 9 - Limitation and Control of Network Ports, Protocols, and Services | Y    | Y    | Y    |

## MITRE ATT&CK Mappings

| Tactic         | Technique                              |
| -------------- | -------------------------------------- |
| Reconnaissance | T1592 - Gather Victim Host Information |
| Reconnaissance | T1592.002 - Software                   |

## Profile

- Level 1 - Authoritative Name Server
- Level 1 - Caching Only Name Server

