Skip to contentExploitQuest

Lesson 1 of 1 in dig

What a Zone Gives Away

Record types, what each one is for, and why the answers you get for free are the start of most engagements.

2 min read

Not yet reviewed

DNS is a public database that answers anybody. Before touching a target at all, you can learn where its mail goes, which provider hosts it, what it has published about who may send on its behalf, and often the names of internal-sounding services somebody forgot were public.

The record types worth knowing

A / AAAA   the address a name resolves to
MX         where mail for this domain goes
NS         which servers are authoritative for the zone
TXT        anything at all - and in practice, policy
CNAME      this name is really that name
  1. Line 2Frequently a third party, which tells you who handles their mail before you have sent a packet to them.
  2. Line 3Delegation. If the NS records point somewhere unexpected, part of this domain is run by somebody other than whoever runs the website.
  3. Line 4SPF, DKIM and DMARC live here, and so do domain-verification strings from every service the organisation has ever signed up to. That list is an inventory of their vendors, published deliberately and read rarely.
  4. Line 5The one that leaks by accident. A CNAME pointing at a service that no longer exists is a dangling record, and dangling records are how subdomain takeover happens.

Note

None of this is intrusion. Every one of those answers is published on purpose, by design, to anyone who asks. That is what makes DNS the first thing anybody looks at and the last thing anybody audits.

Trying it

Your turn

Look up the TXT records for brightpath.example. One of them names a third-party service the organisation uses. Print the records.

you@practice
Practice shell — nothing here is real. Type 'help' to begin.

What it looks like from the other side

Almost nothing. A DNS query goes to a resolver, and the target's own servers may never see it — the answer is very likely cached somewhere in between. This is the quietest reconnaissance there is, which is precisely why it is the first step.

Take care

The defensive move is not detection, because there is nothing reliable to detect. It is auditing what you publish: review your TXT records for services you no longer use, and your CNAMEs for names pointing at infrastructure you no longer own.

Why is a CNAME pointing at a decommissioned service dangerous?