Get the App
SLTechnology News&Howtos  ›  Network Security  › 

DNS domain delivery vulnerability

Shulou Source: shulou.com Published: 2022-06-01 06:52:29 10月03日 Update

Vulnerability principle:

DNS protocol supports the use of axfr-type records for regional transmission to solve the problem of master-slave synchronization. If the administrator does not restrict the source from which records are allowed to be obtained when configuring the DNS server, it will lead to a DNS domain delivery vulnerability.

Recurrence of vulnerabilities:

1. Under Linux, we can use the dig command to send dns requests. We can use dig @ your-ip www.vulhub.org to get the domain name www.vulhub.org to get the A record on the target dns server.

two。 Send a dns request of type axfr: dig @ your-ip-t axfr vulhub.org

It can be seen that I have obtained all the sub-domain name records of vulhub.org, where there is a DNS domain transfer vulnerability.

3. We can also scan for this vulnerability with nmap script: nmap-- script dns-zone-transfer.nse-- script-args "dns-zone-transfer.domain=vulhub.org"-- Pn-p 53 your-ip

Tags: Vulnerabilities servers types services masters and slaves regions principles commands domain names times sources targets administrators problems subdomains synchronization support management configuration restrictions Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Tech Info macOS NVidia Shulou Technology MySQL