EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesMedium

A security auditor is performing an external penetration test against a large corporation. They have identified a public-facing DNS server. To gather as much information as possible about the corporation's internal network structure, the auditor attempts to perform a DNS zone transfer. Which DNS record type, if allowed to be queried by unauthorized sources, would enable a successful zone transfer?

  1. AA (Address) record
  2. BAXFR (Authoritative Zone Transfer) record
  3. CNS (Name Server) record
  4. DMX (Mail Exchange) record
Show answer & explanation

Correct answer: B. AXFR (Authoritative Zone Transfer) record

The AXFR (Authoritative Zone Transfer) record type is specifically used for full zone transfers between DNS servers. If a DNS server is misconfigured to allow AXFR queries from unauthorized sources, an attacker can obtain a complete list of all DNS records for a domain, revealing extensive internal network details.

Why the other options are wrong

  • A. A records map hostnames to IP addresses but do not facilitate a full zone transfer.
  • C. NS records specify authoritative name servers for a domain but do not directly facilitate a full zone transfer, although they are part of DNS enumeration.
  • D. MX records specify mail servers for a domain but do not facilitate a full zone transfer.

DNS Zone Transfer (AXFR)

A mechanism used to replicate DNS database files from a primary DNS server to secondary DNS servers. If misconfigured, it can allow unauthorized users to obtain a complete list of all DNS records for a domain.

  • Uses AXFR query type.
  • Reveals internal network structure.
  • Significant information leakage risk.
  • Countermeasures involve restricting AXFR to trusted IPs.

Memory trick: AXFR: 'All eXtra Files Revealed'.

More Reconnaissance Techniques questions