3 ms·
If a company with a large and complex web property, e.g. Microsoft.com or Google.com, asked you if it mattered whether they allow DNS AXFR, what would your answ
by pmylund 15y ago
If a company with a large and complex web property, e.g. Microsoft.com or Google.com, asked you if it mattered whether they allow DNS AXFR, what would your answer be?
- tptacek 15y agoNobody enables AXFR. AXFR isn't a default. I wouldn't advise someone to override that default. If one of my clients then asked me, "because I don't enable AXFR, is wide-open-dev-machine.customer.com safer?", I would say "no, it is not".
- pmylund 15y agoSo you agree that disabling AXFR, if AXFR is enabled, is a good idea? Could you explain why you think wide-open-dev-machine.customer.com is NOT safer without AXFR (assuming it blocks robots, and the web server only serves the site for "wide-open-dev-machine.customer.com")? I'm just trying to understand how it could not be considered beneficial in any way, however much (which is what you're claiming).
- tptacek 15y agoI don't have to think about this much because nobody has AXFR enabled. If you had AXFR enabled, I would in fact tell you to turn it off. It isn't an operational win (unlike SSH on port 22), so what possible reason could there be for enabling it? wide-open-dev-machine isn't safer because there's a whole variety of ways to learn about it without AXFR. For what it's worth, I would not flag a customer for running SSH on port 22; I would certainly flag a customer for having port 22 exposed where it didn't need to be; for most SaaS/ASP-type companies, I'd flag them for having more than one SSH port exposed, and I'd recommend that they invest in a VPN instead of exposed SSH.
- pmylund 15y agoI think there are far more nameservers allowing AXFR than you think. Write a little app that attempts a zone transfer for the top 1000 of the Alexa list (http://s3.amazonaws.com/alexa-static/top-1m.csv.zip http://s3.amazonaws.com/alexa-static/top-1m.csv.zip) and see for yourself. (Note to anyone reading: Please don't try this before you've checked if it's legal in your state/country or not.) Could you explain how you would learn about wide-open-dev-machine as simply as by using AXFR in your scenario (you aren't on the network, so no *casting). Edit: "so what possible reason could there be for enabling it?" is eerily similar to my message :)
- tptacek 15y agoHere's your answer: imageshack.com about.com ehow.com sparkstudios.com yfrog.com liveinternet.ru pgmediaserve.com wikimedia.com adfly.com thefreedictionary.com amung.us btjunkie.com bluehost.com drtuber.com ero-advertising.com autohome.com.cn exblog.jp inetglobal.com milliyet.com.tr imagebam.com naukri.com bigpoint.com altervista.com hypergames.com gsmarena.com excite.co.jp admagnet.com macrumors.com linkbucks.com cracked.com traidnt.com radikal.ru paper.li eluniversal.com.mx wiktionary.org indianrail.gov.in docin.com 123rf.com perezhilton.com mangafox.com hostmonster.com myfreecams.com giveawayoftheday.com ultimate-guitar.com itpro1.nikkeibp.co.jp pantip.com hawaaworld.com 120ask.com 4.8%. That's more than I would have thought, but it's still a small number: 95.2% of the Alexa 1000 keep AXFR disabled. Also: someone should tell some of these people not to do this.
- pmylund 15y agoIndeed. Keep in mind it's the top, so these are the people you really expect to keep something like that hidden. I promise you the stats are much worse further down the list, or if you do the same, but for a specific country's TLD.