Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Cheap wins before brute-forcing: try AXFR and detect NSEC-walkable zones

Open
#85 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Active
Tech stack
go

Research direction

Start by reading the CLI options and DNS query, rate-limit, and query-accounting paths; the issue also points to the miekg/dns migration proposed in #50. Check how existing tests run and whether they provide a test server that allows AXFR. Done means the transfer is reported, its names are merged into results, and all relevant queries count against the configured limits.

Written by the indexing model from the issue text.

Description

area: dns feature priority: low

Why it matters

  • A misconfigured authoritative server that allows zone transfer (AXFR) gives the complete answer in one query, versus millions of brute-force queries.
  • Zones signed with plain NSEC (not NSEC3) can be walked to list every name.

Checking both first is standard tradecraft (dnsrecon, fierce). It costs almost nothing, and it fits subenum's "minimize queries, trust the result" positioning.

Proposal

  • -axfr (or on by default with a notice):
    • Look up the target's NS records.
    • Attempt AXFR against each authoritative server.
    • On success, report the zone transfer as a finding and merge the names into the results, tagged source: axfr.
  • Detect NSEC versus NSEC3 and print a notice when the zone is walkable. Walking it could be a later -nsec-walk.
  • Charge these queries against -rate and -max-queries.
  • Probably requires the miekg/dns migration proposed in #50, since the stdlib resolver can't do AXFR.

Done when

Against a test server allowing AXFR, subenum reports the transfer and every name in the zone, with the queries counted.

Dominant language
Go
Stars
1
Forks
1
Avg merge
14d 9h
Merged PRs (30d)
1

Getting set up

Open in Codespaces

Starts the project's dev container in your browser, under your own GitHub account.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from TMHSDigital/subenum

All issues in TMHSDigital/subenum

Similar issues

More Go issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.