Comment on How are people discovering random subdomains on my server?
ambitiousslab@lemmy.ml 1 month ago
I believe that some DNS servers are configured to allow zone transfers without any kind of authentication. While properly configured servers will whitelist the IPs of secondaries they trust, for those that don’t, hackers can simply request a zone transfer and get all subdomains at once.
BonkTheAnnoyed@lemmy.blahaj.zone 1 month ago
I don’t have any subdomains registered with DNS.
I attempted
dig axfr example.com @ns1.example.comreturned zone transfer DENIED