Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 98 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Links to cool sites.arrow DNS Zone Transfer
EH-Net
May 26, 2012, 09:04:10 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: DNS Zone Transfer  (Read 2046 times)
0 Members and 1 Guest are viewing this topic.
Ignatius
Jr. Member
**
Offline Offline

Posts: 91


View Profile
« on: January 11, 2012, 04:33:43 AM »

I came across an article written by DigiNinja in which he explains what DNS Zone Transfer is and how information gleaned from misconfiguration might be used.  He registered a domain name and set configurations deliberately in order to demonstrate to clients the dangers of DNS Zone Transfer.

I guess that most sites won't allow this so it may not be of use in a day to day pen test but the article, and accompanying site, might help others to learn details of what DNS Zone Transfer is and the pitfalls of misconfiguration.


Logged
3xban
Sr. Member
****
Offline Offline

Posts: 373


View Profile
« Reply #1 on: January 11, 2012, 07:47:09 AM »

I have found that many valid DNS hosts block the zone transfers from unauthorized systems.  My old company had publically accessible DNS hosted on Windows boxes and it also blocked the ability to drop the requests.  Considering the DNS servers were the same for external and internal, I wanted to make sure that was in place.  For giggles I even tried with my own host and the servers are configured as such. 

Windows 2008 DNS disables unauthorized zone transfers by default.  Now if you can pop a box that is authorized for this, well then you certainly can utilize the attack.  Then again most likely the only systems authorized are other DNS servers.  Its a nice golden egg if you find an open DNS server so never hurts to try.
Logged

Certs: GCWN
lorddicranius
Sr. Member
****
Online Online

Posts: 396



View Profile WWW
« Reply #2 on: January 11, 2012, 09:56:28 AM »

I was listening to the ISD Podcast #560 yesterday and Rob Fuller (mubix) was a guest on there talking about a project he's doing with zone transfers and the entire Internet.  He's going to be presenting at ThotCon.  Looking forward to seeing his results and what he makes of it!
Logged

MaXe
Hero Member
*****
Offline Offline

Posts: 507


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #3 on: January 11, 2012, 04:48:22 PM »

I guess that most sites won't allow this so it may not be of use in a day to day pen test but the article, and accompanying site, might help others to learn details of what DNS Zone Transfer is and the pitfalls of misconfiguration.

A couple of years ago, it was possible on many websites, including anyone using cPanel as there was a configuration bug allowing DNS Zone Transfers aka AXFR requests.

Some websites, such as Wikipedia, deliberately allows transfering their Zone, for debugging purposes they said a long time ago.

The actual command line syntax that is probably the most details is:
Code:
dig @ns.targetnameserver.tld domain.tld AXFR
  Smiley
Logged

I'm an InterN0T'er
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.109 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.