EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesHard

An ethical hacker is performing reconnaissance against a target organization. They discover that the organization uses a specific naming convention for its internal hosts and services (e.g., `web-server01.internal.example.com`, `sql-db01.internal.example.com`). Which of the following enumeration techniques would best leverage this information to discover additional hosts and services that might not be publicly advertised?

  1. APerforming a WHOIS lookup on the main `example.com` domain.
  2. BUsing Google Dorking to find internal documents.
  3. CAttempting a DNS zone transfer for `internal.example.com`.
  4. DScanning external IP ranges with Nmap's default script scan.
Show answer & explanation

Correct answer: C. Attempting a DNS zone transfer for `internal.example.com`.

A DNS zone transfer attempts to copy the entire DNS records for a domain from a DNS server. If the `internal.example.com` DNS server is misconfigured to allow zone transfers, the attacker can obtain a complete list of all hosts and their IP addresses following that naming convention, which is precisely what's needed to leverage the discovered pattern.

Why the other options are wrong

  • A. WHOIS lookups provide domain registration details, not internal host names.
  • B. Google Dorking might find exposed documents, but it's less direct and comprehensive for enumerating internal hosts based on a naming convention than a zone transfer.
  • D. Scanning external IP ranges wouldn't necessarily reveal internal hosts, and Nmap's default script scan is too broad for this specific task.

DNS Zone Transfer

A DNS zone transfer is a mechanism where a secondary DNS server requests a copy of the entire DNS zone file from a primary DNS server. If misconfigured, an attacker can request and obtain this full list of domain records.

  • Used to replicate DNS data between servers.
  • Should be restricted to authorized secondary DNS servers.
  • If allowed for unauthorized requests, it's a critical information disclosure vulnerability.
  • Can reveal all hosts, subdomains, and their IP addresses within a domain.

Memory trick: Naming conventions are a map; a zone transfer is the key to read it all.

More Reconnaissance Techniques questions