daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

5353-udp-multicast-dns-mdns.md (13452B)


      1 ---
      2 title: "5353/UDP Multicast DNS (mDNS) and DNS-SD"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/5353-udp-multicast-dns-mdns.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/5353-udp-multicast-dns-mdns.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 5353/UDP Multicast DNS (mDNS) and DNS-SD
     14 
     15 ## Basic Information
     16 
     17 Multicast DNS (mDNS) provides DNS-like name resolution on a local link without a conventional unicast DNS server. It uses UDP/5353 and the multicast addresses `224.0.0.251` (IPv4) and `FF02::FB` (IPv6). DNS Service Discovery (DNS-SD), commonly carried over mDNS, describes service types and instances using PTR, SRV, TXT, A, and AAAA records.<sup>[[1]](#references)[[7]](#references)[[8]](#references)</sup>
     18 
     19 ```text
     20 PORT     STATE SERVICE
     21 5353/udp open  zeroconf
     22 ```
     23 
     24 Key protocol details relevant to an assessment:<sup>[[7]](#references)</sup>
     25 
     26 - Names in the `.local.` zone are resolved through mDNS.
     27 - The QU (query-unicast) bit can request a unicast reply to a multicast question.
     28 - An mDNS responder must silently discard IPv4 packets whose source is not on the local subnet; for IPv6, it must discard sources other than the local link unless configured as a proxy. Gateways and reflectors intentionally alter this boundary.
     29 - Probing and announcement establish unique host and service names. Forged conflicts can therefore create denial of service or force a device to choose a different name.
     30 
     31 ## DNS-SD service model
     32 
     33 Services use names such as `_<service>._tcp.local.` or `_<service>._udp.local.`. Examples include `_ipp._tcp.local.` (printing), `_airplay._tcp.local.` (AirPlay), and `_adb._tcp.local.` (Android Debug Bridge). Query `_services._dns-sd._udp.local.` to enumerate service types, then resolve instance PTR targets and their SRV/TXT/A/AAAA records.<sup>[[8]](#references)</sup>
     34 
     35 ## Network Exploration and Enumeration
     36 
     37 - nmap target scan (direct mDNS on a host):
     38   ```bash
     39   nmap -sU -p 5353 --script=dns-service-discovery <target>
     40   ```
     41 - nmap broadcast discovery (listen to the segment and enumerate all DNS-SD types/instances):<sup>[[2]](#references)</sup>
     42   ```bash
     43   sudo nmap --script=broadcast-dns-service-discovery
     44   ```
     45 - avahi-browse (Linux):
     46   ```bash
     47   # List service types
     48   avahi-browse -bt _services._dns-sd._udp
     49   # Browse all services and resolve to host/port
     50   avahi-browse -art
     51   ```
     52 - Apple dns-sd (macOS):
     53   ```bash
     54   # Browse all HTTP services
     55   dns-sd -B _http._tcp
     56   # Enumerate service types
     57   dns-sd -B _services._dns-sd._udp
     58   # Resolve a specific instance to SRV/TXT
     59   dns-sd -L "My Printer" _ipp._tcp local
     60   ```
     61 - Packet capture with tshark:
     62   ```bash
     63   # Live capture
     64   sudo tshark -i <iface> -f "udp port 5353" -Y mdns
     65   # Only DNS-SD service list queries
     66   sudo tshark -i <iface> -f "udp port 5353" -Y "dns.qry.name == \"_services._dns-sd._udp.local\""
     67   ```
     68 
     69 Tip: Some WebRTC implementations replace host IP addresses in ICE candidates with temporary mDNS names. A compatible peer resolves those names during ICE processing. If such a candidate appears in authorized signaling or a capture, test its resolution from the same link, but do not assume that every random `.local` name is a stable device hostname or is resolvable outside the browser's lifetime and privacy scope.<sup>[[14]](#references)</sup>
     70 
     71 ## Attacks
     72 
     73 ### mDNS name probing interference (DoS / name squatting)
     74 
     75 During the probing phase, a host checks name uniqueness. Responding with forged conflicts can force it to pick new names or fail, delaying or preventing service registration and discovery. This is disruptive active testing and should be confined to an authorized lab or maintenance window.<sup>[[1]](#references)[[7]](#references)</sup>
     76 
     77 Example using the legacy Python 3 port included in the Pholus repository (confirm the flags against the checked-out revision):<sup>[[9]](#references)</sup>
     78 ```bash
     79 # Block new devices from taking names by auto-faking responses
     80 sudo python3 pholus3.py <iface> -afre -stimeout 1000
     81 ```
     82 
     83 ### Service spoofing and impersonation (MitM)
     84 
     85 In an authorized lab, impersonate advertised DNS-SD services (printers, AirPlay, HTTP, or file shares) to test whether clients authenticate or transmit sensitive content before validating the service. This can:
     86 - Capture documents by spoofing `_ipp._tcp` or `_printer._tcp`.
     87 - Lure clients to HTTP/HTTPS services to harvest tokens/cookies or deliver payloads.
     88 - Capture or relay Windows authentication when a client negotiates NTLM to the spoofed service and the separate relay prerequisites are met.
     89 
     90 With bettercap’s zerogod module (mDNS/DNS-SD spoofer/impersonator):<sup>[[3]](#references)</sup>
     91 ```bash
     92 # Start mDNS/DNS-SD discovery
     93 sudo bettercap -iface <iface> -eval "zerogod.discovery on"
     94 
     95 # Show all services seen from a host
     96 > zerogod.show 192.168.1.42
     97 # Show full DNS records for a host (newer bettercap)
     98 > zerogod.show-full 192.168.1.42
     99 
    100 # Impersonate all services of a target host automatically
    101 > zerogod.impersonate 192.168.1.42
    102 
    103 # Save IPP print jobs to disk while impersonating a printer
    104 > set zerogod.ipp.save_path ~/.bettercap/zerogod/documents/
    105 > zerogod.impersonate 192.168.1.42
    106 
    107 # Replay previously captured services
    108 > zerogod.save 192.168.1.42 target.yml
    109 > zerogod.advertise target.yml
    110 ```
    111 
    112 Also see generic LLMNR/NBNS/mDNS/WPAD spoofing and credential capture/relay workflows:
    113 
    114 [Spoofing Llmnr Nbt Ns Mdns Dns And Wpad And Relay Attacks](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/pentesting-network/spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md)
    115 
    116 ### Notes on implementation vulnerabilities
    117 
    118 - Avahi reachable-assertion bugs CVE-2023-38469 through CVE-2023-38473 and the D-Bus-related CVE-2023-1981 can terminate `avahi-daemon` on affected distributions, disrupting service discovery until it restarts. The exact vectors differ; install the distribution's fixed Avahi package rather than treating the identifiers as one network exploit.<sup>[[12]](#references)</sup>
    119 - Cisco IOS XE Wireless LAN Controller mDNS gateway CVE-2024-20303 allows an unauthenticated adjacent WLAN attacker to send a sustained stream of crafted mDNS traffic, drive controller CPU high, and potentially disconnect AP tunnels. It is a disruptive DoS condition, not a general-purpose roaming primitive.<sup>[[4]](#references)</sup>
    120 - Apple mDNSResponder CVE-2024-44183 allowed a local app to cause denial of service. Apple addressed the logic error in iOS/iPadOS 18; consult the matching advisory for other Apple platform releases.<sup>[[5]](#references)[[15]](#references)</sup>
    121 - Apple mDNSResponder CVE-2025-31222 was a local privilege-escalation correctness issue fixed in macOS Sequoia 15.5. Apple's advisory describes a local user impact; it is not a remote mDNS network exploit and the cited macOS advisory does not establish iPhone impact.<sup>[[6]](#references)[[13]](#references)</sup>
    122 
    123 ### Browser/WebRTC mDNS considerations
    124 
    125 Modern browsers may obfuscate WebRTC host candidates with random mDNS names. On managed Chrome or Edge endpoints, `WebRtcLocalIpsAllowedUrls` permits listed origins to receive local IP addresses in ICE candidates instead. This is a per-origin compatibility policy—not a general mDNS switch—and weakens privacy for the allowed origins. The corresponding `chrome://flags/#enable-webrtc-hide-local-ips-with-mdns` experiment has existed, but flags are version-dependent and should not be used as durable enterprise configuration.<sup>[[10]](#references)</sup>
    126 
    127 On managed Windows Chrome installations, the policy is stored below `HKLM\Software\Policies\Google\Chrome\WebRtcLocalIpsAllowedUrls`, with allowlisted origins represented as numbered string values. Edge uses its own vendor policy path. Prefer the browser's policy UI or enterprise management tooling over editing the registry manually, and verify the effective policy after deployment.<sup>[[10]](#references)[[17]](#references)</sup>
    128 
    129 When that protection is disabled, permitted web applications may receive plain host candidates through ICE signaling. Those IP candidates are not “captured via mDNS”; they replace the obfuscated mDNS names in the WebRTC candidate data.<sup>[[10]](#references)</sup>
    130 
    131 ## Defensive considerations and OPSEC
    132 
    133 - Segment boundaries: Don’t route 224.0.0.251/FF02::FB between security zones unless an mDNS gateway is explicitly required. If you must bridge discovery, prefer allowlists and rate limits.
    134 - Windows endpoints/servers:
    135   - A widely used legacy DNS Client setting is the following value followed by a reboot:
    136     ```
    137     HKLM\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\EnableMDNS = 0 (DWORD)
    138     ```
    139     This affects the Windows DNS Client implementation, not necessarily Bonjour or another application's own responder. Verify the resulting traffic on the exact Windows build.
    140   - In managed environments, disable the built-in “mDNS (UDP-In)” Windows Defender Firewall rule (at least on the Domain profile) to prevent inbound mDNS processing while preserving home/roaming functionality.
    141   - Where the installed ADMX templates expose it, set **Computer Configuration → Administrative Templates → Network → DNS Client → Configure multicast DNS (mDNS) protocol** to **Disabled**. The policy-backed value is `HKLM\Software\Policies\Microsoft\Windows NT\DNSClient\EnableMDNS`; do not confuse this with the older `EnableMulticast` value used for LLMNR.<sup>[[16]](#references)</sup>
    142 - Linux (Avahi):
    143   - Lock down publishing when not needed with `disable-publishing=yes`, and restrict interfaces using `allow-interfaces=` or `deny-interfaces=` in `/etc/avahi/avahi-daemon.conf`.
    144   - Consider `check-response-ttl=yes`. Avoid `enable-reflector=yes` unless required, and use `reflect-filters=` allowlists when reflecting. Note that the Avahi man page warns that enabling both reflection and wide-area DNS may create a security risk.<sup>[[11]](#references)</sup>
    145 - macOS: Restrict inbound mDNS at host/network firewalls when Bonjour discovery is not needed for specific subnets.
    146 - Monitoring: Alert on unusual surges in `_services._dns-sd._udp.local` queries or sudden changes in SRV/TXT of critical services; these are indicators of spoofing or service impersonation.
    147 
    148 ## Tooling quick reference
    149 
    150 - nmap NSE: `dns-service-discovery` and `broadcast-dns-service-discovery`.
    151 - Pholus: legacy active-scan, reverse-mDNS, DoS, and spoofing helpers. The upstream repository is old; run it only in an isolated authorized environment and validate its dependencies and command-line syntax.<sup>[[9]](#references)</sup>
    152   ```bash
    153   # Passive sniff (timeout seconds)
    154   sudo python3 pholus3.py <iface> -stimeout 60
    155   # Enumerate service types
    156   sudo python3 pholus3.py <iface> -sscan
    157   # Send generic mDNS requests
    158   sudo python3 pholus3.py <iface> --request
    159   # Reverse mDNS sweep of a subnet
    160   sudo python3 pholus3.py <iface> -rdns_scanning 192.168.2.0/24
    161   ```
    162 - bettercap zerogod: discover, save, advertise, and impersonate mDNS/DNS-SD services (see examples above).
    163 
    164 ## References
    165 
    166 - [1] [Practical IoT Hacking: The Definitive Guide to Attacking the Internet of Things](https://books.google.co.uk/books/about/Practical_IoT_Hacking.html?id=GbYEEAAAQBAJ&redir_esc=y)
    167 - [2] [Nmap NSE: broadcast-dns-service-discovery](https://nmap.org/nsedoc/scripts/broadcast-dns-service-discovery.html)
    168 - [3] [bettercap zerogod (mDNS/DNS-SD discovery, spoofing, impersonation)](https://www.bettercap.org/modules/ethernet/zerogod/)
    169 - [4] [Cisco IOS XE WLC mDNS gateway DoS (CVE-2024-20303) advisory](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-wlc-mdns-dos-4hv6pBGf.html)
    170 - [5] [Rapid7 advisory for Apple mDNSResponder CVE-2024-44183](https://www.rapid7.com/db/vulnerabilities/apple-mdnsresponder-cve-2024-44183/)
    171 - [6] [Rapid7 writeup of Apple mDNSResponder CVE-2025-31222](https://www.rapid7.com/db/vulnerabilities/apple-osx-mdnsresponder-cve-2025-31222/)
    172 - [7] [RFC 6762 — Multicast DNS](https://www.rfc-editor.org/rfc/rfc6762.html)
    173 - [8] [RFC 6763 — DNS-Based Service Discovery](https://www.rfc-editor.org/rfc/rfc6763.html)
    174 - [9] [Pholus mDNS/DNS-SD assessment toolkit](https://github.com/aatlasis/Pholus)
    175 - [10] [Chrome Enterprise policy — WebRtcLocalIpsAllowedUrls](https://chromeenterprise.google/policies/#WebRtcLocalIpsAllowedUrls)
    176 - [11] [Avahi daemon configuration manual](https://manpages.debian.org/bookworm/avahi-daemon/avahi-daemon.conf.5.en.html)
    177 - [12] [Ubuntu USN-6487-1 — Avahi vulnerabilities](https://ubuntu.com/security/notices/USN-6487-1)
    178 - [13] [Apple security content for macOS Sequoia 15.5](https://support.apple.com/en-us/122716)
    179 - [14] [IETF draft — Using Multicast DNS to protect privacy when exposing ICE candidates](https://datatracker.ietf.org/doc/html/draft-ietf-mmusic-mdns-ice-candidates-03)
    180 - [15] [Apple security content for iOS 18 and iPadOS 18](https://support.apple.com/en-us/121250)
    181 - [16] [Windows policy metadata — Configure multicast DNS (mDNS) protocol](https://policypicker.app/policy/windows/network/dns-client/configure-multicast-dns-mdns-protocol-a84770a8a85d)
    182 - [17] [Chrome Enterprise - Manage Chrome policies with the Windows registry](https://support.google.com/chrome/a/answer/9131254?hl=en)