EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesHard
A security consultant is performing an external penetration test against a client's organization. They discovered that the client's public-facing DNS server allows recursive queries from external IP addresses. Which of the following enumeration techniques could an attacker leverage due to this misconfiguration?
- AReverse DNS Lookup
- BDNSSEC Enumeration
- CDNS Cache Snooping
- DDNS Zone Transfer
Show answer & explanationAnswer & explanation
Correct answer: C. DNS Cache Snooping
Allowing recursive queries from external IP addresses makes a DNS server vulnerable to DNS cache snooping. An attacker can query the server for records it has cached from other domains, revealing internal network information or domains visited by internal users, even if the server is not authoritative for those domains.
Why the other options are wrong
- A. Reverse DNS Lookup translates an IP address to a hostname and is a standard function, not a specific vulnerability related to recursive queries.
- B. DNSSEC Enumeration involves querying DNSSEC records, which is not directly enabled by open recursive queries but rather by the implementation of DNSSEC itself.
- D. DNS Zone Transfer is for retrieving full zone files, which is enabled by misconfigured authoritative servers, not recursive ones.
DNS Cache Snooping
An enumeration technique where an attacker queries a recursive DNS server to determine if it has cached specific DNS records, potentially revealing internal network information or user activity.
- Exploits open recursive DNS servers.
- Reveals cached DNS entries for non-authoritative domains.
- Can expose internal hostnames or external sites visited by the organization.
Memory trick: DNS is the phone book, but sometimes it 'snoops' on your calls.