HN user

lukasfo

1 karma
Posts0
Comments2
View on HN
No posts found.

I strongly disagree, this is 100% vulnerability, you're leaking private DNS records - aka if the name server is also used for private records these are effectively exposed.

There's NO REASON to have zone transfer enabled.

During my 8 years of professional SWE career (mostly startups), I've never worked in a company that did not suffer data breach / was hacked. It was always dumb stuff like admin:admin or deploying vulnerable things and forgetting on them.

After last one, I was done, left my job and started building Recon Wave [0]. I want to build tooling that will monitor your infra for you and find vulnerable / misconfigured / forgotten things that can be easily exploited.

I believe that security is best applied in layers and we're building one of them. We can not protect you from everything, but we can protect you from shooting yourself in the leg.

Me & my co-founder decided to take a bit different approach from other attack surface management companies and we try to find patterns in the whole OSINT world (aka most misconfigurations, domain correlations and others). Among others, we scrapped most of DNS and now have pretty cool reverse DNS dataset [1].

[0] https://reconwave.com/ [1] https://search.reconwave.com/