5 ms·
If it is on DNS, it is discoverable. Even if it were not, the message you pasted says outright that they scan the entire IP space, so they could be hitting your
by codingdave 2y ago
If it is on DNS, it is discoverable. Even if it were not, the message you pasted says outright that they scan the entire IP space, so they could be hitting your server's IP without having a clue there is a subdomain serving your stuff from it.
- govideo 2y agoAhh yeah, my internet network knowledge was never super strong, and now is rusty to boot. Thanks for your note.
- r3db34rd 2y ago[dead]
- EQYV 2y agoQuestion: How does a subdomain get discovered by a member of the public if there are no references to it anywhere online? The only thing I can think of that would let you do that would be a DNS zone transfer request, but those are almost always disallowed from most origin IPs. https://en.m.wikipedia.org/wiki/DNS_zone_transfer https://en.m.wikipedia.org/wiki/DNS_zone_transfer
- dnsfax 2y agoCertificate transparency logs.
- arccy 2y agoyou also have zone walking with DNS NSEC https://www.domaintools.com/resources/blog/zone-walking-zone-enumeration-via-dnssec-nsec-records/ https://www.domaintools.com/resources/blog/zone-walking-zone...
- yatralalala 2y agoSee my comment above https://news.ycombinator.com/item?id=43289743 https://news.ycombinator.com/item?id=43289743 there are many techniques!
- paulnpace 2y agoShouldn't the web server only respond to a configred domain, else 404?
- precommunicator 2y agoDepends if it's configured like that, by default usually no
- dnsfax 2y agoIf you know what to query, sure. You can't just say "give me all subdomains"; it doesn't work that way. The subdomain was discovered via certificate transparency logs.
- alexjplant 2y ago> If it is on DNS, it is discoverable. In the context of what OP is asking this is not true. DNS zones aren't enumerable - the only way to reliably get the complete contents of the zone is to have the SOA server approve a zone transfer and send the zone file to you. You can ask if a record in that zone exists but as a random user you can't say "hand over all records in this zone". I'd imagine that tools like Cloudflare that need this kind of functionality perform a dictionary search since they get 90% of records when importing a domain but always seem to miss inconspicuously-named ones. > Even if it were not, the message you pasted says outright that they scan the entire IP space, so they could be hitting your server's IP without having a clue there is a subdomain serving your stuff from it. This is likely what's happening. If the bot isn't using SNI or sending a host header then they probably found the server by IP. The fact that there's a heretofore unknown DNS record pointing to it is of no consequence. *EDIT: Or the Cert Transparency log as others have mentioned, though this isn't DNS per se. I learn something new every day :o)
- fulafel 2y agoIn practice it's not so far fetched: A zone transfer is just another dns query at the protocol level, i suppose you can conceptually view it as sending a file if you consider the dns response a file. Something like "host -t axfr my.domain ns1.my.domain" will show the zone depending on how a domain's name server is configured (eg in bind, allow-transfer directive can be used to make it public, require ip acl to match the query source, etc).
- elric 2y agoNo sensible DNS provider has zone transfers enabled by default. OP mentioned using CloudFlare, and they certainly don't.
- alexjplant 2y ago> in bind, allow-transfer directive Configuring BIND as an authoritative server for a corporate domain when I was a wee lad is how I learned DNS. It was and still is bad practice to allow zone transfers without auth. If memory serves I locked it down between servers via key pairs.