Comment on How are people discovering random subdomains on my server?
ambitiousslab@lemmy.ml 1 week ago
I believe that some DNS servers are configured to allow zone transfers without any kind of authentication. While properly configured servers will whitelist the IPs of secondaries they trust, for those that don’t, hackers can simply request a zone transfer and get all subdomains at once.
BonkTheAnnoyed@lemmy.blahaj.zone 1 week ago
I don’t have any subdomains registered with DNS.
I attempted
dig axfr example.com @ns1.example.comreturned zone transfer DENIED