daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pentesting-dns.md (14494B)


      1 ---
      2 title: "53 - Pentesting DNS"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-dns.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-dns.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 53 - Pentesting DNS
     14 
     15 ## Basic information
     16 
     17 The **Domain Name System (DNS)** serves as the internet's directory, allowing users to access websites through **easy-to-remember domain names** like google.com or facebook.com, instead of the numeric Internet Protocol (IP) addresses. By translating domain names into IP addresses, the DNS ensures web browsers can quickly load internet resources, simplifying how we navigate the online world.
     18 
     19 **Default port:** 53
     20 
     21 ```text
     22 PORT     STATE SERVICE  REASON
     23 53/tcp   open  domain  Microsoft DNS 6.1.7601 (1DB15D39) (Windows Server 2008 R2 SP1)
     24 5353/udp open  zeroconf udp-response
     25 53/udp   open  domain  Microsoft DNS 6.1.7601 (1DB15D39) (Windows Server 2008 R2 SP1)
     26 ```
     27 
     28 ### Different DNS servers
     29 
     30 - **DNS root servers**: These servers are at the top of the public DNS hierarchy and return referrals for top-level domains. There are 13 named root-server identifiers (`A` through `M`), each implemented by many anycast instances; this does not mean that only 13 physical servers exist.<sup>[[2]](#references)</sup>
     31 - **Authoritative nameservers**: These servers provide authoritative answers for their configured zones, including answers, referrals for delegated child zones, or negative responses. A recursive resolver—not the authoritative server—walks the hierarchy when further lookup is required.
     32 - **Non-authoritative Nameservers**: Lacking ownership over DNS zones, these servers gather domain information through queries to other servers.
     33 - **Caching DNS Server**: This type of server memorizes previous query answers for a set time to speed up response times for future requests, with the cache duration dictated by the authoritative server.
     34 - **Forwarding Server**: Serving a straightforward role, forwarding servers simply relay queries to another server.
     35 - **Resolver**: Integrated within computers or routers, resolvers execute name resolution locally and are not considered authoritative.<sup>[[1]](#references)</sup>
     36 
     37 ## Enumeration
     38 
     39 ### **Banner Grabbing**
     40 
     41 DNS has no conventional service banner, but some BIND servers answer the `version.bind. CHAOS TXT` query. Administrators can disable or replace this value, so an empty or customized response is not conclusive.\
     42 You can perform this query using `dig`:
     43 
     44 ```bash
     45 dig version.bind CHAOS TXT @DNS
     46 ```
     47 
     48 Moreover, the tool [`fpdns`](https://github.com/kirei/fpdns) can also fingerprint the server.
     49 
     50 It's also possible to grab the banner also with a **nmap** script:
     51 
     52 ```text
     53 --script dns-nsid
     54 ```
     55 
     56 ### **Any record**
     57 
     58 An **`ANY`** query asks the DNS server to return whatever record set it is willing and able to provide; modern authoritative servers may intentionally return a minimal response rather than every record.<sup>[[4]](#references)</sup>
     59 
     60 ```bash
     61 dig any victim.com @<DNS_IP>
     62 ```
     63 
     64 ### **Zone Transfer**
     65 
     66 `AXFR` is the DNS mechanism for transferring a complete zone from an authoritative server.<sup>[[3]](#references)</sup>
     67 
     68 ```bash
     69 dig axfr @<DNS_IP> #Try zone transfer without domain
     70 dig axfr @<DNS_IP> <DOMAIN> #Try zone transfer guessing the domain
     71 fierce --domain <DOMAIN> --dns-servers <DNS_IP> #Will try toperform a zone transfer against every authoritative name server and if this doesn'twork, will launch a dictionary attack
     72 ```
     73 
     74 ### More info
     75 
     76 ```bash
     77 dig ANY @<DNS_IP> <DOMAIN>     #Any information
     78 dig A @<DNS_IP> <DOMAIN>       #Regular DNS request
     79 dig AAAA @<DNS_IP> <DOMAIN>    #IPv6 DNS request
     80 dig TXT @<DNS_IP> <DOMAIN>     #Information
     81 dig MX @<DNS_IP> <DOMAIN>      #Emails related
     82 dig NS @<DNS_IP> <DOMAIN>      #DNS that resolves that name
     83 dig -x 192.168.0.2 @<DNS_IP>   #Reverse lookup
     84 dig -x 2a00:1450:400c:c06::93 @<DNS_IP> #reverse IPv6 lookup
     85 
     86 #Use [-p PORT]  or  -6 (to use ivp6 address of dns)
     87 ```
     88 
     89 #### Automation
     90 
     91 ```bash
     92 for sub in $(cat <WORDLIST>);do dig $sub.<DOMAIN> @<DNS_IP> | grep -v ';\|SOA' | sed -r '/^\s*$/d' | grep $sub | tee -a subdomains.txt;done
     93 
     94 dnsenum --dnsserver <DNS_IP> --enum -p 0 -s 0 -o subdomains.txt -f <WORDLIST> <DOMAIN>
     95 ```
     96 
     97 #### Using nslookup
     98 
     99 ```bash
    100 nslookup
    101 > SERVER <IP_DNS> #Select dns server
    102 > 127.0.0.1 #Reverse lookup of 127.0.0.1, maybe...
    103 > <IP_MACHINE> #Reverse lookup of a machine, maybe...
    104 ```
    105 
    106 ### Useful metasploit modules
    107 
    108 ```bash
    109 auxiliary/gather/enum_dns #Perform enumeration actions
    110 ```
    111 
    112 ### Useful nmap scripts
    113 
    114 ```bash
    115 #Perform enumeration actions
    116 nmap -n --script "(default and *dns*) or fcrdns or dns-srv-enum or dns-random-txid or dns-random-srcport" <IP>
    117 ```
    118 
    119 ### DNS - Reverse BF
    120 
    121 ```bash
    122 dnsrecon -r 127.0.0.0/24 -n <IP_DNS>  #DNS reverse of all of the addresses
    123 dnsrecon -r 127.0.1.0/24 -n <IP_DNS>  #DNS reverse of all of the addresses
    124 dnsrecon -r <IP_DNS>/24 -n <IP_DNS>   #DNS reverse of all of the addresses
    125 dnsrecon -d active.htb -a -n <IP_DNS> #Zone transfer
    126 ```
    127 
    128 > [!TIP]
    129 > If subdomains resolve to internal IP addresses, try reverse-DNS brute force against the domain's nameservers for the relevant address range.
    130 
    131 Another tool to do so: [https://github.com/amine7536/reverse-scan](https://github.com/amine7536/reverse-scan)
    132 
    133 You can query reverse IP ranges to [https://bgp.he.net/net/205.166.76.0/24#\_dns](https://bgp.he.net/net/205.166.76.0/24#_dns) (this tool is also helpful with BGP).
    134 
    135 ### DNS - Subdomains BF
    136 
    137 ```bash
    138 dnsenum --dnsserver <IP_DNS> --enum -p 0 -s 0 -o subdomains.txt -f subdomains-1000.txt <DOMAIN>
    139 dnsrecon -D subdomains-1000.txt -d <DOMAIN> -n <IP_DNS>
    140 dnscan -d <domain> -r -w subdomains-1000.txt #Bruteforce subdomains in recursive way, https://github.com/rbsec/dnscan
    141 ```
    142 
    143 ### Active Directory servers
    144 
    145 ```bash
    146 dig -t _gc._tcp.lab.domain.com
    147 dig -t _ldap._tcp.lab.domain.com
    148 dig -t _kerberos._tcp.lab.domain.com
    149 dig -t _kpasswd._tcp.lab.domain.com
    150 
    151 nslookup -type=srv _kerberos._tcp.<CLIENT_DOMAIN>
    152 nslookup -type=srv _kerberos._tcp.domain.com
    153 
    154 nmap --script dns-srv-enum --script-args "dns-srv-enum.domain='domain.com'"
    155 ```
    156 
    157 ### DNSSec
    158 
    159 ```bash
    160  #Query paypal subdomains to ns3.isc-sns.info
    161  nmap -sSU -p53 --script dns-nsec-enum --script-args dns-nsec-enum.domains=paypal.com ns3.isc-sns.info
    162 ```
    163 
    164 ### IPv6
    165 
    166 Brute force using "AAAA" requests to gather IPv6 of the subdomains.
    167 
    168 ```bash
    169 dnsdict6 -s -t <domain>
    170 ```
    171 
    172 Brute-force reverse DNS with IPv6 addresses:
    173 
    174 ```bash
    175 dnsrevenum6 pri.authdns.ripe.net 2001:67c:2e8::/48 #Will use the dns pri.authdns.ripe.net
    176 ```
    177 
    178 ### DNS Recursion DDoS
    179 
    180 If **DNS recursion is enabled**, an attacker could **spoof** the **origin** on the UDP packet in order to make the **DNS send the response to the victim server**. An attacker could abuse **ANY** or **DNSSEC** record types as they use to have the bigger responses.\
    181 The way to **check** if a DNS supports **recursion** is to query a domain name and **check** if the **flag "ra"** (_recursion available_) is in the response:
    182 
    183 ```bash
    184 dig google.com A @<IP>
    185 ```
    186 
    187 **Recursion unavailable:**
    188 
    189 ![IPv6 - DNS Recursion DDoS: dig google.com A @](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28123%29.png)
    190 
    191 **Available**:
    192 
    193 ![IPv6 - DNS Recursion DDoS: DNS Auditor checks (HackTricks tools)](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28146%29.png)
    194 
    195 ### DNS Auditor checks (HackTricks tools)
    196 
    197 The HackTricks Domain/DNS auditor was expanded with extra DNS/certificate checks.  
    198 Use this as a quick manual reference for verification and abuse paths.
    199 
    200 #### NS delegation integrity / lame delegation
    201 
    202 **What it checks**
    203 - Delegated NS hostnames resolve to IPs
    204 - Delegated NSs answer authoritatively for the zone
    205 - SOA serial consistency across authoritative NSs
    206 
    207 **How to check**
    208 ```bash
    209 dig example.com NS +short
    210 for ns in $(dig +short example.com NS); do dig @${ns%?} example.com SOA +short; done
    211 ```
    212 
    213 **Impact**
    214 - Intermittent or full DNS outages
    215 - Stale records depending on which NS a resolver hits
    216 
    217 **Attacker abuse**
    218 - Exploit lame/out-of-sync delegation to increase reliability of cache-poisoning windows and selective traffic disruption.
    219 
    220 #### HTTPS/SVCB modern records
    221 
    222 **What it checks**
    223 - Presence/absence of `HTTPS` and `SVCB` records on apex and `www`
    224 
    225 **How to check**
    226 ```bash
    227 dig example.com HTTPS +short
    228 dig example.com SVCB +short
    229 dig www.example.com HTTPS +short
    230 dig www.example.com SVCB +short
    231 ```
    232 
    233 **Impact**
    234 - Mostly hardening/operational maturity gap (less protocol steering, less explicit service binding)
    235 
    236 **Attacker abuse**
    237 - Not usually direct exploitation, but can reduce defensive control over client connection behavior.
    238 
    239 #### DNS EDNS + TCP fallback resilience
    240 
    241 **What it checks**
    242 - Truncation handling and TCP fallback viability for large DNS/DNSSEC answers
    243 
    244 **How to check**
    245 ```bash
    246 dig example.com DNSKEY +dnssec +bufsize=1232
    247 dig example.com DNSKEY +dnssec +tcp
    248 ```
    249 
    250 **Impact**
    251 - DNSSEC breakage, intermittent resolution failures behind specific networks/firewalls
    252 
    253 **Attacker abuse**
    254 - Trigger degraded availability by forcing large responses where TCP/53 is blocked or broken.
    255 
    256 #### DNSSEC lifecycle (CDS/CDNSKEY + DS consistency)
    257 
    258 **What it checks**
    259 - Presence of rollover signaling records (`CDS`, `CDNSKEY`)
    260 - Parent/child key-tag consistency (`DS` vs `CDS`)
    261 
    262 **How to check**
    263 ```bash
    264 dig example.com DS +short
    265 dig example.com CDS +short
    266 dig example.com CDNSKEY +short
    267 ```
    268 
    269 **Impact**
    270 - Broken key rollover -> validation failures / SERVFAIL for validating resolvers
    271 
    272 **Attacker abuse**
    273 - Abuse mis-rolled states to create denial-of-service conditions for DNSSEC-validating clients.
    274 
    275 #### DNSSEC negative trust validation (NXDOMAIN proofs)
    276 
    277 **What it checks**
    278 - For signed zones, whether random NXDOMAIN responses are validated and carry denial-of-existence evidence
    279 
    280 **How to check**
    281 ```bash
    282 dig @8.8.8.8 _random-does-not-exist.example.com A +dnssec
    283 dig @8.8.8.8 _random-does-not-exist.example.com A +dnssec +multi
    284 ```
    285 
    286 **Impact**
    287 - Broken denial-of-existence behavior can indicate chain/signer inconsistencies
    288 
    289 **Attacker abuse**
    290 - Increase probability of resolver-side failure states during targeted DNSSEC disruption attempts.
    291 
    292 #### Very low TTL on critical records
    293 
    294 **What it checks**
    295 - Low/very-low TTLs on `A`, `AAAA`, `MX`, `NS`
    296 
    297 **How to check**
    298 ```bash
    299 dig example.com A +ttlid
    300 dig example.com AAAA +ttlid
    301 dig example.com MX +ttlid
    302 dig example.com NS +ttlid
    303 ```
    304 
    305 **Impact**
    306 - Faster global propagation of accidental or malicious DNS changes
    307 
    308 **Attacker abuse**
    309 - If attacker gets brief write access to DNS, low TTL accelerates malicious redirection rollout.
    310 
    311 #### CAA policy quality + CT correlation
    312 
    313 **What it checks**
    314 - `issue` / `issuewild` breadth and over-permissive CA authorization
    315 - Whether observed CT issuers are consistent with CAA intent (heuristic)
    316 
    317 **How to check**
    318 ```bash
    319 dig example.com CAA +short
    320 curl -s "https://crt.sh/?q=%25.example.com&output=json" | head
    321 ```
    322 
    323 **Impact**
    324 - Overly broad or inconsistent issuance policy increases cert abuse surface
    325 
    326 **Attacker abuse**
    327 - Mis-scoped CAA can make unauthorized/abusive cert issuance easier after CA/process compromise.
    328 
    329 
    330 ### Mail to nonexistent account
    331 
    332 **Sending an email to a nonexistent address** in the target's domain may trigger a nondelivery notification whose headers disclose internal server names or IP addresses.
    333 
    334 ## Post-Exploitation
    335 
    336 - When reviewing a BIND server, inspect **`allow-transfer`** to determine who can request zone transfers, and **`allow-recursion`** and **`allow-query`** to determine who can send recursive and general queries.
    337 - The following are the names of DNS related files that could be interesting to search inside machines:
    338 
    339 ```text
    340 host.conf
    341 /etc/resolv.conf
    342 /etc/bind/named.conf
    343 /etc/bind/named.conf.local
    344 /etc/bind/named.conf.options
    345 /etc/bind/named.conf.log
    346 /etc/bind/*
    347 ```
    348 
    349 ## HackTricks Automatic Commands
    350 
    351 ```text
    352 Protocol_Name: DNS    #Protocol Abbreviation if there is one.
    353 Port_Number:  53     #Comma separated if there is more than one.
    354 Protocol_Description: Domain Name Service        #Protocol Abbreviation Spelled out
    355 
    356 Entry_1:
    357   Name: Notes
    358   Description: Notes for DNS
    359   Note: |
    360     #These are the commands I run every time I see an open DNS port
    361 
    362     dnsrecon -r 127.0.0.0/24 -n {IP} -d {Domain_Name}
    363     dnsrecon -r 127.0.1.0/24 -n {IP} -d {Domain_Name}
    364     dnsrecon -r {Network}{CIDR} -n {IP} -d {Domain_Name}
    365     dig axfr @{IP}
    366     dig axfr {Domain_Name} @{IP}
    367     nslookup
    368         SERVER {IP}
    369         127.0.0.1
    370         {IP}
    371         Domain_Name
    372         exit
    373 
    374     https://book.hacktricks.wiki/en/todo/pentesting-dns.html
    375 
    376 Entry_2:
    377   Name: Banner Grab
    378   Description: Grab DNS Banner
    379   Command: dig version.bind CHAOS TXT @DNS
    380 
    381 Entry_3:
    382   Name: Nmap Vuln Scan
    383   Description: Scan for Vulnerabilities with Nmap
    384   Command: nmap -n --script "(default and *dns*) or fcrdns or dns-srv-enum or dns-random-txid or dns-random-srcport" {IP}
    385 
    386 Entry_4:
    387   Name: Zone Transfer
    388   Description: Three attempts at forcing a zone transfer
    389   Command: dig axfr @{IP} && dix axfr @{IP} {Domain_Name} && fierce --dns-servers {IP} --domain {Domain_Name}
    390 
    391 
    392 Entry_5:
    393   Name: Active Directory
    394   Description: Eunuerate a DC via DNS
    395   Command: dig -t _gc._{Domain_Name} && dig -t _ldap._{Domain_Name} && dig -t _kerberos._{Domain_Name} && dig -t _kpasswd._{Domain_Name} && nmap --script dns-srv-enum --script-args "dns-srv-enum.domain={Domain_Name}"
    396 
    397 Entry_6:
    398   Name: consolesless mfs enumeration
    399   Description: DNS enumeration without the need to run msfconsole
    400   Note: sourced from https://github.com/carlospolop/legion
    401   Command: msfconsole -q -x 'use auxiliary/scanner/dns/dns_amp; set RHOSTS {IP}; set RPORT 53; run; exit' && msfconsole -q -x 'use auxiliary/gather/enum_dns; set RHOSTS {IP}; set RPORT 53; run; exit'
    402 ```
    403 
    404 ## References
    405 
    406 - [1] [DNS (Domain Name System): definition, function, risks](https://www.myrasecurity.com/en/knowledge-hub/dns/)
    407 - [2] [IANA – Root Servers](https://www.iana.org/domains/root/servers)
    408 - [3] [RFC 5936 – DNS Zone Transfer Protocol (AXFR)](https://www.rfc-editor.org/rfc/rfc5936)
    409 - [4] [RFC 8482 – Minimal Responses to DNS Queries That Have QTYPE=ANY](https://www.rfc-editor.org/rfc/rfc8482)