Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Cheap wins before brute-forcing: try AXFR and detect NSEC-walkable zones

Abierto
#85 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
5/5
Tiempo estimado
Más de una semana
Aptitud para principiantes
35/100
Tipo de issue
Nueva funcionalidad
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
go

Línea de trabajo

Start by reading the CLI options and DNS query, rate-limit, and query-accounting paths; the issue also points to the miekg/dns migration proposed in #50. Check how existing tests run and whether they provide a test server that allows AXFR. Done means the transfer is reported, its names are merged into results, and all relevant queries count against the configured limits.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

area: dns feature priority: low

Why it matters

  • A misconfigured authoritative server that allows zone transfer (AXFR) gives the complete answer in one query, versus millions of brute-force queries.
  • Zones signed with plain NSEC (not NSEC3) can be walked to list every name.

Checking both first is standard tradecraft (dnsrecon, fierce). It costs almost nothing, and it fits subenum's "minimize queries, trust the result" positioning.

Proposal

  • -axfr (or on by default with a notice):
    • Look up the target's NS records.
    • Attempt AXFR against each authoritative server.
    • On success, report the zone transfer as a finding and merge the names into the results, tagged source: axfr.
  • Detect NSEC versus NSEC3 and print a notice when the zone is walkable. Walking it could be a later -nsec-walk.
  • Charge these queries against -rate and -max-queries.
  • Probably requires the miekg/dns migration proposed in #50, since the stdlib resolver can't do AXFR.

Done when

Against a test server allowing AXFR, subenum reports the transfer and every name in the zone, with the queries counted.

Lenguaje dominante
Go
Estrellas
1
Forks
1
Merge medio
5 d 2 h
PR fusionados (30 d)
3

Preparar el entorno

Abrir en Codespaces

Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de TMHSDigital/subenum

Todos los issues de TMHSDigital/subenum

Issues similares

Más issues de Go

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.