Domain Name System (DNS) translates domain names to the numeral IP addresses. It uses UDP/53 but will rely on TCP/53 more heavily as time progresses.
DNS Zone Transfer
A DNS Zone is a portion of the DNS namespace that a specific organization or administrator manages. Since DNS comprises multiple DNS zones, DNS servers utilize DNS zone transfer to copy a portion of their database to another DNS server. Unless a DNS server limits which IPs can perform DNS zone transfers, anyone can ask a DNS server for a copy of its zone information since DNS zone transfers do not require any authentication.
An attacker could use DNS zone transfers to learn more about an organization’s DNS namespace, increasing the attack surface.
# dump the entire DNS namespace
dig AXFR @ns1.inlanefreight.htb inlanefreight.htbDomain and Subdomain Takeover Review
Registering a non-existent domain name to gain control over another domain. If attacker find an expired domain, they can claim that domain to perform further attacks such as hosting malicious content on a website or sending a phishing email.
Subdomain takeover is also possible. CNAME record is used to map different domains to a parent domain. Companies can point a subdomain to another domain, if for some reason that domain they point the subdomain to expires, an attacker can take control of the subdomain.
# enumerate all DNS servers of the root domain
fierce --domain zonetransfer.me
# enumerate subdomains for a target domain
./subfinder -d inlanefreight.com -v
# use self-defined resolvers and perform pure DNS brute-forcing
./subbrute.py inlanefreight.com -s ./names.txt -r ./resolvers.txt
# enumerate the CNAME records for those subdomains
host support.inlanefreight.com DNS Spoofing
Also DNS Cache Poisoning. Involves altering legitimate DNS records with false information so that they can be used to redirect online traffic to a fraudulent website.
Local DNS Cache Poisoning invovles an attacker using MITM tools.
# before using edit the /etc/ettercap/etter.dns to map the target domain name that they want to spoof to attacker's IP
cat /etc/ettercap/etter.dns
# then star the Ettercap tool
# 1. Scan for live hosts Hosts > Scan for Hosts
# 2. Add the target IP address to
# 3.