rozumbrada 6 hours ago

Wow I hear for the first time that some TLD registrar would explicitelly allow zone transfer of the whole zone... talking about the Swedish TLD mentioned in the article.

This really works

dig @zonedata.iis.se se axfr

ujakelos 6 hours ago

maybe controversial take, but zone transfers are not vulnerability, there's nothing really private in that

  • lukasfo 6 hours ago

    I strongly disagree, this is 100% vulnerability, you're leaking private DNS records - aka if the name server is also used for private records these are effectively exposed.

    There's NO REASON to have zone transfer enabled.

    • nobody9999 4 hours ago

      >There's NO REASON to have zone transfer enabled.

      There are absolutely reasons to have zone transfer enabled -- to transfer the zones from primary/authoritative DNS servers to secondary DNS servers.

      Zone transfers should, however, be limited to just the secondary DNS servers and not open to the world.