Some interesting DNS data https://news.ycombinator.com/item?id=46159249
201 karma · joined August 11, 2020
jj@reconwave.com
Some interesting DNS data https://news.ycombinator.com/item?id=46159249
GoDaddy and Cloudflare alone host ~106 millions of domains – about one-third of all the domains. The top 10 providers sit on over half of all the domains.
What we build is primarily focused on companies that have at least hybrid stack - some on prem, some in cloud. If you completely behind load balancer and have strict change management, we can't bring you any value.
In ideal world, we wouldn't have any business. But oh boy... Companies host wild stuff.
Every single conversation I had with clients ended up with us showing some of their infra and the response was "wow, we didn't know this is ours".
Recon Wave basically finds and scans all their services - DNS, IPs, Apps, Ports - and notify customers when it breaks some policy (aka. "no ports than 443 should be open") or when some service is straight vulnerable.
I'm former security engineer and I hated all that "critical reports" that reported missing CSP header.
We're now playing with an idea to build LLM pentesting agent that could run agains the whole infra of our customers.
Finding all things about domains is one of the things that we do. And yes, it's very easy.
There are many services like subdomainfinder - i.e. dnsdumpster and merklemap. We built our own as well on https://search.reconwave.com/. But it's a side project and it does not pay our bills.
It's basically the way how to get all DNS records a DNS server has. Interestingly in some countries this is illegal and in some this is considered best practice.
Generally, enabled zone transfers is considered as misconfiguration and should be disabled.
We did research on that few months back and found out that 8% of all global name servers have it enabled.[0]
[0] - https://reconwave.com/blog/post/alarming-prevalence-of-zone-...
This way, you will force everyone to go through Cloudflare and utilize all those fancy bot blocking features they have.
But I'd say there's no issue if everything else is secured properly.
We built global reverse-DNS dataset solely from cert transparency logs. Our active scanning/bruteforcing runs only for assets owned by our customers.
Great example is port knocking - it hides your open port from random nmap, but would you leave it as the only mechanism preventing people getting to your server? No. So does it make sense to have it? Well maybe, it's a layer.
Kerckhoffs' principle comes to my mind as well here.
So while I agree with you on that's obscurity is fine strategy, you can never depend on it ever.
The options how to find it are basically limitless. Best source is probably Certificate Transparency project as others suggested. But it does not end there, some other things that we do are things like internet crawl, domain bruteforcing on wildcard dns, dangling vhosts identification, default certs on servers (connect to IP on 443 and get default cert) and many others.
Security by obscurity does not work. You can not rely on "people won't find it". Once it's online, everyone can find it. No matter how you hide it.
non "paywalled" link: https://threadreaderapp.com/thread/1852021884902138123.html
[0] https://reconwave.com/blog/post/storing-private-keys-in-txt-...
[0] https://www.reddit.com/r/sysadmin/comments/1fn3f25/found_rsa...
Fully opensourced, with test coverage between 60-70% and a single dependency for logging.