Re: question regarding nessus plug-in 10595 DNS AXFR

From: Ariel Martinez (ariel_at_muiscas.udea.edu.co)
Date: 02/25/04

  • Next message: Travis Schack: "Re: question regarding nessus plug-in 10595 DNS AXFR"
    Date: Tue, 24 Feb 2004 20:06:48 -0500 (COT)
    To: cissper <cissper@yahoo.com.au>
    
    

    On Tue, 24 Feb 2004, cissper wrote:

    [...]

    > In one of my scans, nessus reported a vulnerability allowing DNS zone
    > transfers (see below). I have tried to verify this vulnerability
    > manually with nslookup and other tools. Apparently a manual DNS zone
    > transfer did not work! So I am just wondering if anybody knows what this
    > plug-in is exactly doing. I am not yet familiar with the scripting
    > language used.

    I guess plugin tried an AXFR for a reverse zone not for a forward zone.
    You can try dig(1) or host(1) from bind-utils to get the whole reverse
    zone for 192.168.1.*:

    $ dig @dns-server 1.168.192.in-addr.arpa axfr # You can append +notcp to
    force udp query.
     
    $ host -l 1.168.192.in-addr.arpa dns-server

    --
    Ariel Martinez.
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    

  • Next message: Travis Schack: "Re: question regarding nessus plug-in 10595 DNS AXFR"

    Relevant Pages

    • Re: DNS Zone Transfer on SBS 2003 Premium
      ... > companyname.com primary zone is hosted locally and will ... The ISA protocol rules and server ... > zone transfers to listed name servers, ... (I enabled the debug logging on the DNS ...
      (microsoft.public.windows.server.dns)
    • Re: Single Answer Zone Transfer
      ... I was asked if Windows 2003 DNS support "Single Answer Zone Transfers". ... But for normal AD replication only changes are sent, ...
      (microsoft.public.windows.server.dns)
    • DNS zone transfer problems on SBS 2003 Premium
      ... companyname.com primary zone is hosted locally and will ... The ISA protocol rules and server ... zone transfers to listed name servers, ... (I enabled the debug logging on the DNS ...
      (microsoft.public.windows.server.sbs)
    • RE: zone transfers, a spammers dream?
      ... zone transfers, a spammer's dream? ... Much to my surprise the whole fm zone was transferable by anyone. ... to get the number of domains, as this lists multiple name servers per ... Best regards, ...
      (Bugtraq)
    • Re: Event ID 3150 W2K3 new setup
      ... > Went ahead and created Reverse Zone and PTR record and am ... I assume this indicates a Forward Lookup Zone ... > issue as timeout is Reverse Zone related. ... > same nslookup error, PCD seems to be working well. ...
      (microsoft.public.windows.server.dns)