Nmap Development mailing list archives

Re: NSEC Enumeration script


From: John Bond <john.r.bond () gmail com>
Date: Wed, 9 Feb 2011 21:11:06 +0100

On 8 February 2011 21:58, John Bond <john.r.bond () gmail com> wrote:
This might be a dumb question, but does it work with NSEC3 servers?
I have made an update so that the library almost recognises NSEC3 (for
some reason the hash looks like its about a byte to big).  and the
nsec-enum script will error with NSEC3 not supported

updated the enum script to resolve the enumerated records.  output
now like this

53/udp open  domain  udp-response
| dns-nsec-enum:        hosts for example.com:
|       ns.example.com:NS:SOA:RRSIG:NSEC:DNSKEY
|       www.example.com:A:RRSIG:NSEC
|               3.3.3.3
|       ftp.example.com:A:RRSIG:NSEC
|               2.2.2.2
|       x.example.com:CNAME:RRSIG:NSEC
|       y.example.com:A:RRSIG:NSEC
|               1.1.1.1

Attachment: dns-nsec-enum.nse
Description:

_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/

Current thread: