Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Cheap wins before brute-forcing: try AXFR and detect NSEC-walkable zones

Aperta
#85 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
35/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
go

Direzione di ricerca

Start by reading the CLI options and DNS query, rate-limit, and query-accounting paths; the issue also points to the miekg/dns migration proposed in #50. Check how existing tests run and whether they provide a test server that allows AXFR. Done means the transfer is reported, its names are merged into results, and all relevant queries count against the configured limits.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

area: dns feature priority: low

Why it matters

  • A misconfigured authoritative server that allows zone transfer (AXFR) gives the complete answer in one query, versus millions of brute-force queries.
  • Zones signed with plain NSEC (not NSEC3) can be walked to list every name.

Checking both first is standard tradecraft (dnsrecon, fierce). It costs almost nothing, and it fits subenum's "minimize queries, trust the result" positioning.

Proposal

  • -axfr (or on by default with a notice):
    • Look up the target's NS records.
    • Attempt AXFR against each authoritative server.
    • On success, report the zone transfer as a finding and merge the names into the results, tagged source: axfr.
  • Detect NSEC versus NSEC3 and print a notice when the zone is walkable. Walking it could be a later -nsec-walk.
  • Charge these queries against -rate and -max-queries.
  • Probably requires the miekg/dns migration proposed in #50, since the stdlib resolver can't do AXFR.

Done when

Against a test server allowing AXFR, subenum reports the transfer and every name in the zone, with the queries counted.

Lingua principale
Go
Stelle
1
Fork
1
Merge medio
14g 9h
PR unite (30g)
1

Preparare l'ambiente

Apri in Codespaces

Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di TMHSDigital/subenum

Tutte le issue di TMHSDigital/subenum

Issue simili

Altre issue su Go

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.