Vulnerability Development mailing list archives

Re: DNS zone transfer


From: Ralf Vitasek <ralfv () ralfv de>
Date: Sun, 09 Jun 2002 17:35:41 +0200

Vlad wrote:
Greetings,

Is it possible to remotely retrieve all DNS records from a server
*without* knowing the specific zones it hosts? (cause then I can script "dig @dns-server.ip zone-domain ALL" )

If it matters the server runs the DNS service on Win2k and I've got no
preferance for Windows or *NIX tools. Any will do.


Thanks,
 - Vlad.



i doubt that such a thing is possible, i would think of an information leak otherwise. for the dns`s servers (all bind on linux) i always even prohibit axfr's for domains to unathorized hosts (i.e. i just allow my secondary nameservers to do that).

what *good* use anyone could have for such a thing?
if you have any reason to know these you could arrange an interchange of the nameservers config file via scp for example.

regards
ralf




Current thread: