Comment on How are people discovering random subdomains on my server?

ambitiousslab@lemmy.ml ⁨1⁩ ⁨week⁩ ago

I believe that some DNS servers are configured to allow zone transfers without any kind of authentication. While properly configured servers will whitelist the IPs of secondaries they trust, for those that don’t, hackers can simply request a zone transfer and get all subdomains at once.

source
Sort:hotnewtop