Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

Cheap wins before brute-forcing: try AXFR and detect NSEC-walkable zones

Aberta
#85 0 comentários 0 reações 0 responsáveis Ver no GitHub

Mantenedores costumam responder em até 1 dia

Ninguém assumiu esta issue ainda.

Avaliação

Dificuldade
5/5
Tempo estimado
Mais de uma semana
Facilidade para iniciantes
35/100
Tipo de issue
Funcionalidade
Clareza
Razoavelmente clara
Status de atividade
Ativa
Stack de tecnologia
go
Domínio
cli, networking, security

Direção de pesquisa

Start by reading the CLI options and DNS query, rate-limit, and query-accounting paths; the issue also points to the miekg/dns migration proposed in #50. Check how existing tests run and whether they provide a test server that allows AXFR. Done means the transfer is reported, its names are merged into results, and all relevant queries count against the configured limits.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

area: dns feature priority: low

Why it matters

  • A misconfigured authoritative server that allows zone transfer (AXFR) gives the complete answer in one query, versus millions of brute-force queries.
  • Zones signed with plain NSEC (not NSEC3) can be walked to list every name.

Checking both first is standard tradecraft (dnsrecon, fierce). It costs almost nothing, and it fits subenum's "minimize queries, trust the result" positioning.

Proposal

  • -axfr (or on by default with a notice):
    • Look up the target's NS records.
    • Attempt AXFR against each authoritative server.
    • On success, report the zone transfer as a finding and merge the names into the results, tagged source: axfr.
  • Detect NSEC versus NSEC3 and print a notice when the zone is walkable. Walking it could be a later -nsec-walk.
  • Charge these queries against -rate and -max-queries.
  • Probably requires the miekg/dns migration proposed in #50, since the stdlib resolver can't do AXFR.

Done when

Against a test server allowing AXFR, subenum reports the transfer and every name in the zone, with the queries counted.

Linguagem predominante
Go
Estrelas
1
Forks
1
Merge médio
5d 2h
PRs com merge (30d)
3

Preparar o ambiente

Abrir no Codespaces

Inicia o contêiner de desenvolvimento do projeto no navegador, com a sua própria conta do GitHub.

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de TMHSDigital/subenum

Todas as issues de TMHSDigital/subenum

Issues semelhantes

Mais issues de Go

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.