Re: DNS zone transfer

From: Eric Monti (EMON44@CBOT.COM)
Date: 06/10/02


Date: Mon, 10 Jun 2002 09:05:35 -0500
From: "Eric Monti" <EMON44@CBOT.COM>
To: <progman@netvision.net.il>, <vuln-dev@securityfocus.com>


I dont think there is a mechanism in most DNS server implementations to quickly find out all the domains it's authoritative/secondary for. But might it be possible to acheive the same effect using some creative whois queries against domain registries?

What I'm thinking about is that usually (not always) the registry assigns a handle to DNS servers when they are included/added as servers for domains. Does anyone know if there is a way to query for all domains served by a given DNS server's handle?

-e

>>> Vlad <progman@netvision.net.il> 06/08/02 09:00AM >>>
Greetings,

Is it possible to remotely retrieve all DNS records from a server
*without* knowing the specific zones it hosts?
(cause then I can script "dig @dns-server.ip zone-domain ALL" )

If it matters the server runs the DNS service on Win2k and I've got no
preferance for Windows or *NIX tools. Any will do.

Thanks,
 - Vlad.



Relevant Pages

  • Re: potential replication problems --
    ... the "enable journal wrap automatic restore" registry hack and was ... replmon and sonar look fine on both servers ... Active Directory could not use DNS to resolve the IP address of the ... source domain controller listed below... ...
    (microsoft.public.windows.server.active_directory)
  • Re: Help SMPT Errors
    ... FAIL Reverse DNS entries for MX records ERROR: The IP of one or more of your ... it may mean that your DNS servers did not respond fast enough). ... INFO NS records at parent servers Your NS records at the parent servers ... PASS Parent nameservers have your nameservers listed OK. ...
    (microsoft.public.exchange.admin)
  • Re: Replication issues
    ... I wanted to say Zone Transfers not Zone Forwarding. ... on 2 servers out of 4 DNS servers. ... DNS and 2003 DNS and how to set up Conditional Forwarding. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Windows 2000 logon process
    ... Paul Williams ... when clients are accessing the GPO stored in SYSVOL during logon. ... PW>> Sound's like - that's a combination of DNS and Dfs client pointing ... Global Catalogue servers? ...
    (microsoft.public.win2000.active_directory)
  • Re: Howto refresh IIS 6 Application pool identity credential info
    ... You already have 80% of the work setup (DNS Aliases and HostHeaders) on the ... domain accounts (one for each layer) should be sufficient. ... The Application Servers are load balanced clustered, ... as the account name and SPN alias is correctly defined on both nodes. ...
    (microsoft.public.inetserver.iis.security)