CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
A penetration tester is performing reconnaissance against a target organization's public-facing infrastructure. They suspect that the organization's DNS server might be misconfigured to allow unauthorized zone transfers. The tester attempts to retrieve DNS zone information for `example.com` from `ns1.example.com` using the command `dig axfr @ns1.example.com example.com`. If the command is successful and returns a full list of DNS records, what vulnerability has been identified?
- ADNS Zone Transfer Misconfiguration
- BDNS Cache Poisoning
- CDNS Rebinding
- DDNSSEC Bypass
Show answer & explanationAnswer & explanation
Correct answer: A. DNS Zone Transfer Misconfiguration
The `dig axfr` command specifically requests a full DNS zone transfer. If a DNS server responds successfully to this request from an unauthorized client, it indicates a DNS Zone Transfer Misconfiguration. This allows an attacker to obtain a complete map of the organization's network, including hostnames, IP addresses, and other sensitive information.
Why the other options are wrong
- B. DNS Cache Poisoning involves corrupting a DNS resolver's cache, not requesting a zone transfer.
- C. DNS Rebinding is used to bypass same-origin policy, typically in web application contexts, not for enumerating DNS records directly.
- D. DNSSEC Bypass involves circumventing DNSSEC validations, which is not what `dig axfr` tests for.
DNS Zone Transfer Misconfiguration
A vulnerability where a DNS server is configured to allow full zone transfers (AXFR) to unauthorized clients. This can expose sensitive internal network information, including hostnames and IP addresses.
- Uses `AXFR` (Asynchronous Zone Transfer Full Request).
- Exposes all DNS records for a domain.
- Provides a detailed map of the target's network infrastructure.
- Typically occurs due to improper `allow-transfer` settings.
Memory trick: DNS: Cache, Rebind, Transfer, Bypass – each a different way to mess with names.