logo

DNSSEC NSEC. The accidental treasure map to your subdomains

ID: 69aac944-8293-5e82-bc87-0b4cbb72fb9e

STIX ID: report--69aac944-8293-5e82-bc87-0b4cbb72fb9e

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2025-03-04

Date Updated: 2026-03-24

Author: Darrell Hall

...
...

This report explains how DNSSEC’s NSEC and NSEC3 mechanisms can enable DNS zone walking, allowing attackers to enumerate domains and subdomains even when AXFR is blocked. It details practical methods for NSEC-based enumeration, NSEC3 hash collection and cracking (including parameters like salt and iterations), and differences from zone transfers. The report recommends mitigations such as properly configured NSEC3 with strong parameters and DNSSEC “White Lies” to reduce enumeration risk while balancing privacy, operational overhead, and security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.