CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
A penetration tester is conducting a reconnaissance phase and suspects that a target organization might have internal DNS records that are not publicly exposed but could be useful for further enumeration. They want to attempt a DNS zone transfer from the primary DNS server. Which command would they use for this purpose?
- Adig axfr @<dns_server_ip> <target_domain>
- Bwhois <target_domain>
- Cnslookup -type=any <target_domain>
- Dhost -l <target_domain> <dns_server_ip>
Show answer & explanationAnswer & explanation
Correct answer: A. dig axfr @<dns_server_ip> <target_domain>
The 'dig axfr' command is specifically used to request a full zone transfer (AXFR) from a DNS server. If the DNS server is misconfigured to allow zone transfers from unauthorized sources, this command will retrieve all DNS records for the specified domain.
Why the other options are wrong
- B. whois retrieves domain registration information, not DNS zone records.
- C. nslookup -type=any queries all record types but does not attempt a zone transfer.
- D. host -l attempts to list all records for a domain from a specific server, which is similar to a zone transfer but 'dig axfr' is the more precise and direct command for AXFR.
DNS Zone Transfer (AXFR)
A mechanism used to replicate DNS database files (zone files) from a primary DNS server to secondary DNS servers. If misconfigured, it can be exploited to obtain a complete list of a domain's DNS records, including internal hosts.
- Uses the 'AXFR' (Asynchronous Full Zone Transfer) query type.
- Should typically be restricted to authorized secondary DNS servers.
- A successful transfer reveals all DNS records for a domain.
- The 'dig' utility is commonly used to perform this.
Memory trick: DNS queries unveil network names.