
136 lines
5.2 KiB
Raw Normal View History

2023-10-28 14:55:58 -07:00
#!/usr/bin/env python
# Mass DNS AXFR - developed by acidvegas in python (
2023-10-28 21:45:10 -07:00
import logging
2023-10-28 18:40:06 -07:00
import os
2023-10-28 21:45:10 -07:00
import random
2023-10-28 14:55:58 -07:00
import urllib.request
import dns.rdatatype
import dns.query
import dns.resolver
except ImportError:
raise SystemExit('missing required \'dnspython\' module (pip install dnspython)')
2023-10-28 18:40:06 -07:00
def attempt_axfr(tld: str, nameserver: str, filename: str):
2023-10-28 14:55:58 -07:00
Perform a DNS zone transfer on a target domain.
:param target: The target domain to perform the zone transfer on.
:param nameserver: The nameserver to perform the zone transfer on.
2023-10-28 18:40:06 -07:00
:param filename: The filename to store the zone transfer results in.
2023-10-28 14:55:58 -07:00
2023-10-28 18:40:06 -07:00
temp_file = filename + '.temp'
if not (nameserver := resolve_nameserver(nameserver)):
2023-10-28 18:40:06 -07:00
logging.error(f'Failed to resolve nameserver {nameserver}: {ex}')
for ns in nameserver: # Let's try all the IP addresses for the nameserver
with open(temp_file, 'w') as file:
xfr = dns.query.xfr(nameserver.address, tld+'.', lifetime=300)
for msg in xfr:
for rrset in msg.answer:
for rdata in rrset:
file.write(f'{}.{tld} {rrset.ttl} {rdata}\n')
os.rename(temp_file, filename)
except Exception as ex:
if os.path.exists(temp_file):
logging.error(f'Failed to perform zone transfer from {nameserver.address} for {tld}: {ex}')
2023-10-28 14:55:58 -07:00
2023-10-28 18:40:06 -07:00
def get_root_nameservers() -> list:
2023-10-28 14:55:58 -07:00
'''Generate a list of the root nameservers.'''
2023-10-28 21:45:10 -07:00
root_ns_records = dns.resolver.resolve('.', 'NS', lifetime=15)
2023-10-28 18:40:06 -07:00
root_servers = [str([:-1] for rr in root_ns_records]
return root_servers
2023-10-28 14:55:58 -07:00
2023-10-28 14:55:58 -07:00
def get_root_tlds() -> list:
'''Get the root TLDs from IANA.'''
2023-10-28 21:45:10 -07:00
tlds = urllib.request.urlopen('').read().decode('utf-8').lower().split('\n')[1:]
return tlds
2023-10-28 14:55:58 -07:00
2023-10-28 18:40:06 -07:00
def get_tld_nameservers(tld: str) -> list:
2023-10-28 14:55:58 -07:00
'''Get the nameservers for a TLD.'''
2023-10-28 21:45:10 -07:00
return [str(nameserver) for nameserver in dns.resolver.resolve(tld+'.', 'NS', lifetime=60)]
2023-10-28 21:45:10 -07:00
except dns.exception.Timeout:
logging.warning(f"Timeout fetching nameservers for TLD: {tld}")
except dns.resolver.NoNameservers:
logging.warning(f"No nameservers found for TLD: {tld}")
return []
2023-10-28 14:55:58 -07:00
def get_psl_tlds() -> list:
'''Download the Public Suffix List and return its contents.'''
data = urllib.request.urlopen('').read().decode()
domains = []
for line in data.split('\n'):
if line.startswith('//') or not line:
if '*' in line or '!' in line:
if '.' not in line:
return domains
2023-10-28 18:40:06 -07:00
def resolve_nameserver(nameserver: str) -> str:
2023-10-28 14:55:58 -07:00
Resolve a nameserver to its IP address.
:param nameserver: The nameserver to resolve.
data = []
for version in ('A', 'AAAA'):
data += [ip.address for ip in dns.resolver.resolve(nameserver, version, lifetime=60)]
return data
2023-10-28 14:55:58 -07:00
if __name__ == '__main__':
2023-10-28 18:40:06 -07:00
import argparse
2023-10-28 21:45:10 -07:00
import concurrent.futures
2023-10-28 18:40:06 -07:00
parser = argparse.ArgumentParser(description='Mass DNS AXFR')
2023-10-28 21:45:10 -07:00
parser.add_argument('-c', '--concurrency', type=int, default=30, help='maximum concurrent tasks')
2023-10-28 18:40:06 -07:00
parser.add_argument('-o', '--output', default='axfrout', help='output directory')
2023-10-28 21:45:10 -07:00
parser.add_argument('-t', '--timeout', type=int, default=30, help='DNS timeout (default: 30)')
2023-10-28 18:40:06 -07:00
args = parser.parse_args()
2023-10-28 21:45:10 -07:00
os.makedirs(args.output, exist_ok=True)
dns.resolver._DEFAULT_TIMEOUT = args.timeout
2023-10-28 18:40:06 -07:00
2023-10-28 21:45:10 -07:00
with concurrent.futures.ThreadPoolExecutor(max_workers=args.concurrency) as executor:
2023-10-28 23:12:17 -07:00
futures = [executor.submit(attempt_axfr, '', root, os.path.join(args.output, root + '.txt')) for root in get_root_nameservers()]
2023-10-28 21:45:10 -07:00
for future in concurrent.futures.as_completed(futures):
except Exception as e:
logging.error(f'Error in root server task: {e}')
2023-10-28 14:55:58 -07:00
2023-10-28 21:45:10 -07:00
with concurrent.futures.ThreadPoolExecutor(max_workers=args.concurrency) as executor:
futures = [executor.submit(attempt_axfr, tld, ns, os.path.join(args.output, tld + '.txt')) for tld in get_root_tlds() for ns in get_tld_nameservers(tld) if ns]
for future in concurrent.futures.as_completed(futures):
except Exception as e:
logging.error(f'Error in TLD task: {e}')
with concurrent.futures.ThreadPoolExecutor(max_workers=args.concurrency) as executor:
futures = [executor.submit(attempt_axfr, tld, ns, os.path.join(args.output, tld + '.txt')) for tld in get_psl_tlds() for ns in get_tld_nameservers(tld) if ns]
2023-10-28 21:45:10 -07:00
for future in concurrent.futures.as_completed(futures):
except Exception as e:
logging.error(f'Error in TLD task: {e}')