anonymous Zonetransfer (AXFR) exploatation

From: xx yy (thenucker2004@yahoo.com)
Date: Wed Mar 12 2008 - 17:55:18 EST


During some research I came across some server that have anonymous Zonetransfer (AXFR) allowed.

Is there a working attack for a DNS server that has anonymous Zonetransfer (AXFR) allowed ?

I will appreciate any detailed description of what can be done to dig deeper into this potential vulnerability.
Also if anyone knows of some good resources for AXFR exploatation please share.

Thanks

__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:58:27 EDT