pentesting-dns.md (14494B)
1 --- 2 title: "53 - Pentesting DNS" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-dns.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-dns.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 53 - Pentesting DNS 14 15 ## Basic information 16 17 The **Domain Name System (DNS)** serves as the internet's directory, allowing users to access websites through **easy-to-remember domain names** like google.com or facebook.com, instead of the numeric Internet Protocol (IP) addresses. By translating domain names into IP addresses, the DNS ensures web browsers can quickly load internet resources, simplifying how we navigate the online world. 18 19 **Default port:** 53 20 21 ```text 22 PORT STATE SERVICE REASON 23 53/tcp open domain Microsoft DNS 6.1.7601 (1DB15D39) (Windows Server 2008 R2 SP1) 24 5353/udp open zeroconf udp-response 25 53/udp open domain Microsoft DNS 6.1.7601 (1DB15D39) (Windows Server 2008 R2 SP1) 26 ``` 27 28 ### Different DNS servers 29 30 - **DNS root servers**: These servers are at the top of the public DNS hierarchy and return referrals for top-level domains. There are 13 named root-server identifiers (`A` through `M`), each implemented by many anycast instances; this does not mean that only 13 physical servers exist.<sup>[[2]](#references)</sup> 31 - **Authoritative nameservers**: These servers provide authoritative answers for their configured zones, including answers, referrals for delegated child zones, or negative responses. A recursive resolver—not the authoritative server—walks the hierarchy when further lookup is required. 32 - **Non-authoritative Nameservers**: Lacking ownership over DNS zones, these servers gather domain information through queries to other servers. 33 - **Caching DNS Server**: This type of server memorizes previous query answers for a set time to speed up response times for future requests, with the cache duration dictated by the authoritative server. 34 - **Forwarding Server**: Serving a straightforward role, forwarding servers simply relay queries to another server. 35 - **Resolver**: Integrated within computers or routers, resolvers execute name resolution locally and are not considered authoritative.<sup>[[1]](#references)</sup> 36 37 ## Enumeration 38 39 ### **Banner Grabbing** 40 41 DNS has no conventional service banner, but some BIND servers answer the `version.bind. CHAOS TXT` query. Administrators can disable or replace this value, so an empty or customized response is not conclusive.\ 42 You can perform this query using `dig`: 43 44 ```bash 45 dig version.bind CHAOS TXT @DNS 46 ``` 47 48 Moreover, the tool [`fpdns`](https://github.com/kirei/fpdns) can also fingerprint the server. 49 50 It's also possible to grab the banner also with a **nmap** script: 51 52 ```text 53 --script dns-nsid 54 ``` 55 56 ### **Any record** 57 58 An **`ANY`** query asks the DNS server to return whatever record set it is willing and able to provide; modern authoritative servers may intentionally return a minimal response rather than every record.<sup>[[4]](#references)</sup> 59 60 ```bash 61 dig any victim.com @<DNS_IP> 62 ``` 63 64 ### **Zone Transfer** 65 66 `AXFR` is the DNS mechanism for transferring a complete zone from an authoritative server.<sup>[[3]](#references)</sup> 67 68 ```bash 69 dig axfr @<DNS_IP> #Try zone transfer without domain 70 dig axfr @<DNS_IP> <DOMAIN> #Try zone transfer guessing the domain 71 fierce --domain <DOMAIN> --dns-servers <DNS_IP> #Will try toperform a zone transfer against every authoritative name server and if this doesn'twork, will launch a dictionary attack 72 ``` 73 74 ### More info 75 76 ```bash 77 dig ANY @<DNS_IP> <DOMAIN> #Any information 78 dig A @<DNS_IP> <DOMAIN> #Regular DNS request 79 dig AAAA @<DNS_IP> <DOMAIN> #IPv6 DNS request 80 dig TXT @<DNS_IP> <DOMAIN> #Information 81 dig MX @<DNS_IP> <DOMAIN> #Emails related 82 dig NS @<DNS_IP> <DOMAIN> #DNS that resolves that name 83 dig -x 192.168.0.2 @<DNS_IP> #Reverse lookup 84 dig -x 2a00:1450:400c:c06::93 @<DNS_IP> #reverse IPv6 lookup 85 86 #Use [-p PORT] or -6 (to use ivp6 address of dns) 87 ``` 88 89 #### Automation 90 91 ```bash 92 for sub in $(cat <WORDLIST>);do dig $sub.<DOMAIN> @<DNS_IP> | grep -v ';\|SOA' | sed -r '/^\s*$/d' | grep $sub | tee -a subdomains.txt;done 93 94 dnsenum --dnsserver <DNS_IP> --enum -p 0 -s 0 -o subdomains.txt -f <WORDLIST> <DOMAIN> 95 ``` 96 97 #### Using nslookup 98 99 ```bash 100 nslookup 101 > SERVER <IP_DNS> #Select dns server 102 > 127.0.0.1 #Reverse lookup of 127.0.0.1, maybe... 103 > <IP_MACHINE> #Reverse lookup of a machine, maybe... 104 ``` 105 106 ### Useful metasploit modules 107 108 ```bash 109 auxiliary/gather/enum_dns #Perform enumeration actions 110 ``` 111 112 ### Useful nmap scripts 113 114 ```bash 115 #Perform enumeration actions 116 nmap -n --script "(default and *dns*) or fcrdns or dns-srv-enum or dns-random-txid or dns-random-srcport" <IP> 117 ``` 118 119 ### DNS - Reverse BF 120 121 ```bash 122 dnsrecon -r 127.0.0.0/24 -n <IP_DNS> #DNS reverse of all of the addresses 123 dnsrecon -r 127.0.1.0/24 -n <IP_DNS> #DNS reverse of all of the addresses 124 dnsrecon -r <IP_DNS>/24 -n <IP_DNS> #DNS reverse of all of the addresses 125 dnsrecon -d active.htb -a -n <IP_DNS> #Zone transfer 126 ``` 127 128 > [!TIP] 129 > If subdomains resolve to internal IP addresses, try reverse-DNS brute force against the domain's nameservers for the relevant address range. 130 131 Another tool to do so: [https://github.com/amine7536/reverse-scan](https://github.com/amine7536/reverse-scan) 132 133 You can query reverse IP ranges to [https://bgp.he.net/net/205.166.76.0/24#\_dns](https://bgp.he.net/net/205.166.76.0/24#_dns) (this tool is also helpful with BGP). 134 135 ### DNS - Subdomains BF 136 137 ```bash 138 dnsenum --dnsserver <IP_DNS> --enum -p 0 -s 0 -o subdomains.txt -f subdomains-1000.txt <DOMAIN> 139 dnsrecon -D subdomains-1000.txt -d <DOMAIN> -n <IP_DNS> 140 dnscan -d <domain> -r -w subdomains-1000.txt #Bruteforce subdomains in recursive way, https://github.com/rbsec/dnscan 141 ``` 142 143 ### Active Directory servers 144 145 ```bash 146 dig -t _gc._tcp.lab.domain.com 147 dig -t _ldap._tcp.lab.domain.com 148 dig -t _kerberos._tcp.lab.domain.com 149 dig -t _kpasswd._tcp.lab.domain.com 150 151 nslookup -type=srv _kerberos._tcp.<CLIENT_DOMAIN> 152 nslookup -type=srv _kerberos._tcp.domain.com 153 154 nmap --script dns-srv-enum --script-args "dns-srv-enum.domain='domain.com'" 155 ``` 156 157 ### DNSSec 158 159 ```bash 160 #Query paypal subdomains to ns3.isc-sns.info 161 nmap -sSU -p53 --script dns-nsec-enum --script-args dns-nsec-enum.domains=paypal.com ns3.isc-sns.info 162 ``` 163 164 ### IPv6 165 166 Brute force using "AAAA" requests to gather IPv6 of the subdomains. 167 168 ```bash 169 dnsdict6 -s -t <domain> 170 ``` 171 172 Brute-force reverse DNS with IPv6 addresses: 173 174 ```bash 175 dnsrevenum6 pri.authdns.ripe.net 2001:67c:2e8::/48 #Will use the dns pri.authdns.ripe.net 176 ``` 177 178 ### DNS Recursion DDoS 179 180 If **DNS recursion is enabled**, an attacker could **spoof** the **origin** on the UDP packet in order to make the **DNS send the response to the victim server**. An attacker could abuse **ANY** or **DNSSEC** record types as they use to have the bigger responses.\ 181 The way to **check** if a DNS supports **recursion** is to query a domain name and **check** if the **flag "ra"** (_recursion available_) is in the response: 182 183 ```bash 184 dig google.com A @<IP> 185 ``` 186 187 **Recursion unavailable:** 188 189  190 191 **Available**: 192 193  194 195 ### DNS Auditor checks (HackTricks tools) 196 197 The HackTricks Domain/DNS auditor was expanded with extra DNS/certificate checks. 198 Use this as a quick manual reference for verification and abuse paths. 199 200 #### NS delegation integrity / lame delegation 201 202 **What it checks** 203 - Delegated NS hostnames resolve to IPs 204 - Delegated NSs answer authoritatively for the zone 205 - SOA serial consistency across authoritative NSs 206 207 **How to check** 208 ```bash 209 dig example.com NS +short 210 for ns in $(dig +short example.com NS); do dig @${ns%?} example.com SOA +short; done 211 ``` 212 213 **Impact** 214 - Intermittent or full DNS outages 215 - Stale records depending on which NS a resolver hits 216 217 **Attacker abuse** 218 - Exploit lame/out-of-sync delegation to increase reliability of cache-poisoning windows and selective traffic disruption. 219 220 #### HTTPS/SVCB modern records 221 222 **What it checks** 223 - Presence/absence of `HTTPS` and `SVCB` records on apex and `www` 224 225 **How to check** 226 ```bash 227 dig example.com HTTPS +short 228 dig example.com SVCB +short 229 dig www.example.com HTTPS +short 230 dig www.example.com SVCB +short 231 ``` 232 233 **Impact** 234 - Mostly hardening/operational maturity gap (less protocol steering, less explicit service binding) 235 236 **Attacker abuse** 237 - Not usually direct exploitation, but can reduce defensive control over client connection behavior. 238 239 #### DNS EDNS + TCP fallback resilience 240 241 **What it checks** 242 - Truncation handling and TCP fallback viability for large DNS/DNSSEC answers 243 244 **How to check** 245 ```bash 246 dig example.com DNSKEY +dnssec +bufsize=1232 247 dig example.com DNSKEY +dnssec +tcp 248 ``` 249 250 **Impact** 251 - DNSSEC breakage, intermittent resolution failures behind specific networks/firewalls 252 253 **Attacker abuse** 254 - Trigger degraded availability by forcing large responses where TCP/53 is blocked or broken. 255 256 #### DNSSEC lifecycle (CDS/CDNSKEY + DS consistency) 257 258 **What it checks** 259 - Presence of rollover signaling records (`CDS`, `CDNSKEY`) 260 - Parent/child key-tag consistency (`DS` vs `CDS`) 261 262 **How to check** 263 ```bash 264 dig example.com DS +short 265 dig example.com CDS +short 266 dig example.com CDNSKEY +short 267 ``` 268 269 **Impact** 270 - Broken key rollover -> validation failures / SERVFAIL for validating resolvers 271 272 **Attacker abuse** 273 - Abuse mis-rolled states to create denial-of-service conditions for DNSSEC-validating clients. 274 275 #### DNSSEC negative trust validation (NXDOMAIN proofs) 276 277 **What it checks** 278 - For signed zones, whether random NXDOMAIN responses are validated and carry denial-of-existence evidence 279 280 **How to check** 281 ```bash 282 dig @8.8.8.8 _random-does-not-exist.example.com A +dnssec 283 dig @8.8.8.8 _random-does-not-exist.example.com A +dnssec +multi 284 ``` 285 286 **Impact** 287 - Broken denial-of-existence behavior can indicate chain/signer inconsistencies 288 289 **Attacker abuse** 290 - Increase probability of resolver-side failure states during targeted DNSSEC disruption attempts. 291 292 #### Very low TTL on critical records 293 294 **What it checks** 295 - Low/very-low TTLs on `A`, `AAAA`, `MX`, `NS` 296 297 **How to check** 298 ```bash 299 dig example.com A +ttlid 300 dig example.com AAAA +ttlid 301 dig example.com MX +ttlid 302 dig example.com NS +ttlid 303 ``` 304 305 **Impact** 306 - Faster global propagation of accidental or malicious DNS changes 307 308 **Attacker abuse** 309 - If attacker gets brief write access to DNS, low TTL accelerates malicious redirection rollout. 310 311 #### CAA policy quality + CT correlation 312 313 **What it checks** 314 - `issue` / `issuewild` breadth and over-permissive CA authorization 315 - Whether observed CT issuers are consistent with CAA intent (heuristic) 316 317 **How to check** 318 ```bash 319 dig example.com CAA +short 320 curl -s "https://crt.sh/?q=%25.example.com&output=json" | head 321 ``` 322 323 **Impact** 324 - Overly broad or inconsistent issuance policy increases cert abuse surface 325 326 **Attacker abuse** 327 - Mis-scoped CAA can make unauthorized/abusive cert issuance easier after CA/process compromise. 328 329 330 ### Mail to nonexistent account 331 332 **Sending an email to a nonexistent address** in the target's domain may trigger a nondelivery notification whose headers disclose internal server names or IP addresses. 333 334 ## Post-Exploitation 335 336 - When reviewing a BIND server, inspect **`allow-transfer`** to determine who can request zone transfers, and **`allow-recursion`** and **`allow-query`** to determine who can send recursive and general queries. 337 - The following are the names of DNS related files that could be interesting to search inside machines: 338 339 ```text 340 host.conf 341 /etc/resolv.conf 342 /etc/bind/named.conf 343 /etc/bind/named.conf.local 344 /etc/bind/named.conf.options 345 /etc/bind/named.conf.log 346 /etc/bind/* 347 ``` 348 349 ## HackTricks Automatic Commands 350 351 ```text 352 Protocol_Name: DNS #Protocol Abbreviation if there is one. 353 Port_Number: 53 #Comma separated if there is more than one. 354 Protocol_Description: Domain Name Service #Protocol Abbreviation Spelled out 355 356 Entry_1: 357 Name: Notes 358 Description: Notes for DNS 359 Note: | 360 #These are the commands I run every time I see an open DNS port 361 362 dnsrecon -r 127.0.0.0/24 -n {IP} -d {Domain_Name} 363 dnsrecon -r 127.0.1.0/24 -n {IP} -d {Domain_Name} 364 dnsrecon -r {Network}{CIDR} -n {IP} -d {Domain_Name} 365 dig axfr @{IP} 366 dig axfr {Domain_Name} @{IP} 367 nslookup 368 SERVER {IP} 369 127.0.0.1 370 {IP} 371 Domain_Name 372 exit 373 374 https://book.hacktricks.wiki/en/todo/pentesting-dns.html 375 376 Entry_2: 377 Name: Banner Grab 378 Description: Grab DNS Banner 379 Command: dig version.bind CHAOS TXT @DNS 380 381 Entry_3: 382 Name: Nmap Vuln Scan 383 Description: Scan for Vulnerabilities with Nmap 384 Command: nmap -n --script "(default and *dns*) or fcrdns or dns-srv-enum or dns-random-txid or dns-random-srcport" {IP} 385 386 Entry_4: 387 Name: Zone Transfer 388 Description: Three attempts at forcing a zone transfer 389 Command: dig axfr @{IP} && dix axfr @{IP} {Domain_Name} && fierce --dns-servers {IP} --domain {Domain_Name} 390 391 392 Entry_5: 393 Name: Active Directory 394 Description: Eunuerate a DC via DNS 395 Command: dig -t _gc._{Domain_Name} && dig -t _ldap._{Domain_Name} && dig -t _kerberos._{Domain_Name} && dig -t _kpasswd._{Domain_Name} && nmap --script dns-srv-enum --script-args "dns-srv-enum.domain={Domain_Name}" 396 397 Entry_6: 398 Name: consolesless mfs enumeration 399 Description: DNS enumeration without the need to run msfconsole 400 Note: sourced from https://github.com/carlospolop/legion 401 Command: msfconsole -q -x 'use auxiliary/scanner/dns/dns_amp; set RHOSTS {IP}; set RPORT 53; run; exit' && msfconsole -q -x 'use auxiliary/gather/enum_dns; set RHOSTS {IP}; set RPORT 53; run; exit' 402 ``` 403 404 ## References 405 406 - [1] [DNS (Domain Name System): definition, function, risks](https://www.myrasecurity.com/en/knowledge-hub/dns/) 407 - [2] [IANA – Root Servers](https://www.iana.org/domains/root/servers) 408 - [3] [RFC 5936 – DNS Zone Transfer Protocol (AXFR)](https://www.rfc-editor.org/rfc/rfc5936) 409 - [4] [RFC 8482 – Minimal Responses to DNS Queries That Have QTYPE=ANY](https://www.rfc-editor.org/rfc/rfc8482)