Cheap wins before brute-forcing: try AXFR and detect NSEC-walkable zones
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- go
- Domain
- cli, networking, security
Research direction
Start by reading the CLI options and DNS query, rate-limit, and query-accounting paths; the issue also points to the miekg/dns migration proposed in #50. Check how existing tests run and whether they provide a test server that allows AXFR. Done means the transfer is reported, its names are merged into results, and all relevant queries count against the configured limits.
Written by the indexing model from the issue text.
Description
Why it matters
- A misconfigured authoritative server that allows zone transfer (AXFR) gives the complete answer in one query, versus millions of brute-force queries.
- Zones signed with plain NSEC (not NSEC3) can be walked to list every name.
Checking both first is standard tradecraft (dnsrecon, fierce). It costs almost nothing, and it fits subenum's "minimize queries, trust the result" positioning.
Proposal
-axfr(or on by default with a notice):- Look up the target's NS records.
- Attempt AXFR against each authoritative server.
- On success, report the zone transfer as a finding and merge the names into the results, tagged
source: axfr.
- Detect NSEC versus NSEC3 and print a notice when the zone is walkable. Walking it could be a later
-nsec-walk. - Charge these queries against
-rateand-max-queries. - Probably requires the miekg/dns migration proposed in #50, since the stdlib resolver can't do AXFR.
Done when
Against a test server allowing AXFR, subenum reports the transfer and every name in the zone, with the queries counted.
- Dominant language
- Go
- Stars
- 1
- Forks
- 1
- Avg merge
- 14d 9h
- Merged PRs (30d)
- 1
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- Ships a Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from TMHSDigital/subenum
-
documentation testing
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
TMHSDigital/subenum#103 ·
Maintainers usually reply within 1 day
-
area: release bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
TMHSDigital/subenum#102 ·
Maintainers usually reply within 1 day
-
community marketing priority: low
Difficulty 5/5 Over a week Newbie friendliness 35/100
TMHSDigital/subenum#132 ·
Maintainers usually reply within 1 day
-
feature priority: low
Difficulty 5/5 Over a week Newbie friendliness 35/100
TMHSDigital/subenum#131 ·
Maintainers usually reply within 1 day
-
documentation marketing priority: medium
Difficulty 5/5 Over a week Newbie friendliness 25/100
TMHSDigital/subenum#127 ·
Maintainers usually reply within 1 day
All issues in TMHSDigital/subenum
Similar issues
-
[submenu] nil issue on ubuntu 26.04Possibly taken @egoist claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
prime-radiant-inc/evener#3873 ·
Maintainers usually reply within 1 day
-
extract_llm_sweep / cache_aware_summarizer prefix ask 400s when thinking.budget_tokens exceeds PrefixAskMaxTokensPossibly taken @amiddavid claimed this today. Open
Difficulty 1/5 Under an hour Newbie friendliness 85/100
rossoctl/context-guru#405 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 80/100
router-for-me/CLIProxyAPI#6423 ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 2 days