EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesMedium
A security auditor is performing an external penetration test against a large corporation. They have identified a public-facing DNS server. To gather as much information as possible about the corporation's internal network structure, the auditor attempts to perform a DNS zone transfer. Which DNS record type, if allowed to be queried by unauthorized sources, would enable a successful zone transfer?
- AA (Address) record
- BAXFR (Authoritative Zone Transfer) record
- CNS (Name Server) record
- DMX (Mail Exchange) record
Show answer & explanationAnswer & explanation
Correct answer: B. AXFR (Authoritative Zone Transfer) record
The AXFR (Authoritative Zone Transfer) record type is specifically used for full zone transfers between DNS servers. If a DNS server is misconfigured to allow AXFR queries from unauthorized sources, an attacker can obtain a complete list of all DNS records for a domain, revealing extensive internal network details.
Why the other options are wrong
- A. A records map hostnames to IP addresses but do not facilitate a full zone transfer.
- C. NS records specify authoritative name servers for a domain but do not directly facilitate a full zone transfer, although they are part of DNS enumeration.
- D. MX records specify mail servers for a domain but do not facilitate a full zone transfer.
DNS Zone Transfer (AXFR)
A mechanism used to replicate DNS database files from a primary DNS server to secondary DNS servers. If misconfigured, it can allow unauthorized users to obtain a complete list of all DNS records for a domain.
- Uses AXFR query type.
- Reveals internal network structure.
- Significant information leakage risk.
- Countermeasures involve restricting AXFR to trusted IPs.
Memory trick: AXFR: 'All eXtra Files Revealed'.