Cheap wins before brute-forcing: try AXFR and detect NSEC-walkable zones
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 35/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- go
- Área
- cli, networking, security
Línea de trabajo
Start by reading the CLI options and DNS query, rate-limit, and query-accounting paths; the issue also points to the miekg/dns migration proposed in #50. Check how existing tests run and whether they provide a test server that allows AXFR. Done means the transfer is reported, its names are merged into results, and all relevant queries count against the configured limits.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Why it matters
- A misconfigured authoritative server that allows zone transfer (AXFR) gives the complete answer in one query, versus millions of brute-force queries.
- Zones signed with plain NSEC (not NSEC3) can be walked to list every name.
Checking both first is standard tradecraft (dnsrecon, fierce). It costs almost nothing, and it fits subenum's "minimize queries, trust the result" positioning.
Proposal
-axfr(or on by default with a notice):- Look up the target's NS records.
- Attempt AXFR against each authoritative server.
- On success, report the zone transfer as a finding and merge the names into the results, tagged
source: axfr.
- Detect NSEC versus NSEC3 and print a notice when the zone is walkable. Walking it could be a later
-nsec-walk. - Charge these queries against
-rateand-max-queries. - Probably requires the miekg/dns migration proposed in #50, since the stdlib resolver can't do AXFR.
Done when
Against a test server allowing AXFR, subenum reports the transfer and every name in the zone, with the queries counted.
- Lenguaje dominante
- Go
- Estrellas
- 1
- Forks
- 1
- Merge medio
- 5 d 2 h
- PR fusionados (30 d)
- 3
Preparar el entorno
Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.
- Incluye un Dockerfile o un archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de TMHSDigital/subenum
-
area: cli enhancement good first issue
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
TMHSDigital/subenum#136 ·
Los mantenedores suelen responder en 1 día
-
community documentation good first issue
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
TMHSDigital/subenum#135 ·
Los mantenedores suelen responder en 1 día
-
area: dns enhancement good first issue
Dificultad 2/5 Menos de una hora Aptitud para principiantes 90/100
TMHSDigital/subenum#134 ·
Los mantenedores suelen responder en 1 día
-
community marketing priority: low
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
TMHSDigital/subenum#132 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
feature priority: low
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
TMHSDigital/subenum#131 ·
Los mantenedores suelen responder en 1 día
Todos los issues de TMHSDigital/subenum
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
prime-radiant-inc/evener#4223 ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
open-telemetry/opentelemetry-go-compile-instrumentation#1467 ·
Los mantenedores suelen responder en 3 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
yetone/magpie#1490 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 1/5 Menos de una hora Aptitud para principiantes 72/100
Los mantenedores suelen responder en 1 día
-
a:bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 80/100
gotify/server#1068 · 1 reacción ·
Los mantenedores suelen responder en 2 días