m0rtem / CloudFail

Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network
MIT License
2.18k stars 463 forks source link

Question? #115

Open AnonymousRonin opened 1 month ago

AnonymousRonin commented 1 month ago

Here's the result of dnsrecon:

[] std: Performing General Enumeration against: goodmanre.com... [] Checking for Zone Transfer for goodmanre.com name servers [] Resolving SOA Record [+] SOA anuj.ns.cloudflare.com 172.64.33.65 [+] SOA anuj.ns.cloudflare.com 108.162.193.65 [+] SOA anuj.ns.cloudflare.com 173.245.59.65 [+] SOA anuj.ns.cloudflare.com 2a06:98c1:50::ac40:2141 [+] SOA anuj.ns.cloudflare.com 2606:4700:58::adf5:3b41 [+] SOA anuj.ns.cloudflare.com 2803:f800:50::6ca2:c141 [] Resolving NS Records [] NS Servers found: [+] NS anuj.ns.cloudflare.com 172.64.33.65 [+] NS anuj.ns.cloudflare.com 108.162.193.65 [+] NS anuj.ns.cloudflare.com 173.245.59.65 [+] NS anuj.ns.cloudflare.com 2606:4700:58::adf5:3b41 [+] NS anuj.ns.cloudflare.com 2a06:98c1:50::ac40:2141 [+] NS anuj.ns.cloudflare.com 2803:f800:50::6ca2:c141 [+] NS rose.ns.cloudflare.com 108.162.192.141 [+] NS rose.ns.cloudflare.com 172.64.32.141 [+] NS rose.ns.cloudflare.com 173.245.58.141 [+] NS rose.ns.cloudflare.com 2a06:98c1:50::ac40:208d [+] NS rose.ns.cloudflare.com 2606:4700:50::adf5:3a8d [+] NS rose.ns.cloudflare.com 2803:f800:50::6ca2:c08d [] Removing any duplicate NS server IP Addresses... []
[
] Trying NS server 2803:f800:50::6ca2:c141 [-] Zone Transfer Failed for 2803:f800:50::6ca2:c141! [-] Port 53 TCP is being filtered []
[
] Trying NS server 108.162.192.141 [+] 108.162.192.141 Has port 53 TCP Open [-] Zone Transfer Failed (Zone transfer error: FORMERR) []
[
] Trying NS server 2a06:98c1:50::ac40:2141 [-] Zone Transfer Failed for 2a06:98c1:50::ac40:2141! [-] Port 53 TCP is being filtered []
[
] Trying NS server 173.245.59.65 [+] 173.245.59.65 Has port 53 TCP Open [-] Zone Transfer Failed (Zone transfer error: FORMERR) []
[
] Trying NS server 2606:4700:50::adf5:3a8d [-] Zone Transfer Failed for 2606:4700:50::adf5:3a8d! [-] Port 53 TCP is being filtered []
[
] Trying NS server 172.64.33.65 [+] 172.64.33.65 Has port 53 TCP Open [-] Zone Transfer Failed (Zone transfer error: FORMERR) []
[
] Trying NS server 2803:f800:50::6ca2:c08d [-] Zone Transfer Failed for 2803:f800:50::6ca2:c08d! [-] Port 53 TCP is being filtered []
[
] Trying NS server 173.245.58.141 [+] 173.245.58.141 Has port 53 TCP Open [-] Zone Transfer Failed (Zone transfer error: FORMERR) []
[
] Trying NS server 108.162.193.65 [+] 108.162.193.65 Has port 53 TCP Open [-] Zone Transfer Failed (Zone transfer error: FORMERR) []
[
] Trying NS server 2a06:98c1:50::ac40:208d [-] Zone Transfer Failed for 2a06:98c1:50::ac40:208d! [-] Port 53 TCP is being filtered []
[
] Trying NS server 172.64.32.141 [+] 172.64.32.141 Has port 53 TCP Open [-] Zone Transfer Failed (Zone transfer error: FORMERR) []
[
] Trying NS server 2606:4700:58::adf5:3b41 [-] Zone Transfer Failed for 2606:4700:58::adf5:3b41! [-] Port 53 TCP is being filtered [] Checking for Zone Transfer for goodmanre.com name servers [] Resolving SOA Record [+] SOA anuj.ns.cloudflare.com 173.245.59.65 [+] SOA anuj.ns.cloudflare.com 172.64.33.65 [+] SOA anuj.ns.cloudflare.com 108.162.193.65 [+] SOA anuj.ns.cloudflare.com 2803:f800:50::6ca2:c141 [+] SOA anuj.ns.cloudflare.com 2606:4700:58::adf5:3b41 [+] SOA anuj.ns.cloudflare.com 2a06:98c1:50::ac40:2141 [] Resolving NS Records [] NS Servers found: [+] NS anuj.ns.cloudflare.com 173.245.59.65 [+] NS anuj.ns.cloudflare.com 108.162.193.65 [+] NS anuj.ns.cloudflare.com 172.64.33.65 [+] NS anuj.ns.cloudflare.com 2606:4700:58::adf5:3b41 [+] NS anuj.ns.cloudflare.com 2803:f800:50::6ca2:c141 [+] NS anuj.ns.cloudflare.com 2a06:98c1:50::ac40:2141 [+] NS rose.ns.cloudflare.com 108.162.192.141 [+] NS rose.ns.cloudflare.com 173.245.58.141 [+] NS rose.ns.cloudflare.com 172.64.32.141 [+] NS rose.ns.cloudflare.com 2a06:98c1:50::ac40:208d [+] NS rose.ns.cloudflare.com 2803:f800:50::6ca2:c08d [+] NS rose.ns.cloudflare.com 2606:4700:50::adf5:3a8d [] Removing any duplicate NS server IP Addresses... []
[] Trying NS server 2803:f800:50::6ca2:c141 [-] Zone Transfer Failed for 2803:f800:50::6ca2:c141! [-] Port 53 TCP is being filtered []
[] Trying NS server 108.162.192.141 [+] 108.162.192.141 Has port 53 TCP Open [-] Zone Transfer Failed (Zone transfer error: FORMERR) []
[] Trying NS server 2a06:98c1:50::ac40:2141 [-] Zone Transfer Failed for 2a06:98c1:50::ac40:2141! [-] Port 53 TCP is being filtered []
[] Trying NS server 173.245.59.65 [+] 173.245.59.65 Has port 53 TCP Open [-] Zone Transfer Failed (Zone transfer error: FORMERR) []
[] Trying NS server 2606:4700:50::adf5:3a8d [-] Zone Transfer Failed for 2606:4700:50::adf5:3a8d! [-] Port 53 TCP is being filtered []
[] Trying NS server 172.64.33.65 [+] 172.64.33.65 Has port 53 TCP Open [-] Zone Transfer Failed (Zone transfer error: FORMERR) []
[] Trying NS server 2803:f800:50::6ca2:c08d [-] Zone Transfer Failed for 2803:f800:50::6ca2:c08d! [-] Port 53 TCP is being filtered []
[] Trying NS server 173.245.58.141 [+] 173.245.58.141 Has port 53 TCP Open [-] Zone Transfer Failed (Zone transfer error: FORMERR) []
[] Trying NS server 108.162.193.65 [+] 108.162.193.65 Has port 53 TCP Open [-] Zone Transfer Failed (Zone transfer error: FORMERR) []
[] Trying NS server 2a06:98c1:50::ac40:208d [-] Zone Transfer Failed for 2a06:98c1:50::ac40:208d! [-] Port 53 TCP is being filtered []
[] Trying NS server 172.64.32.141 [+] 172.64.32.141 Has port 53 TCP Open [-] Zone Transfer Failed (Zone transfer error: FORMERR) []
[] Trying NS server 2606:4700:58::adf5:3b41 [-] Zone Transfer Failed for 2606:4700:58::adf5:3b41! [-] Port 53 TCP is being filtered [] DNSSEC is configured for goodmanre.com [] DNSKEYs: [] NSEC KSk ECDSAP256SHA256 99db2cc14cabdc33d6d77da63a2f15f7 1112584f234e8d1dc428e39e8a4a97e1 aa271a555dc90701e17e2a4c4b6f120b 7c32d44f4ac02bd894cf2d4be7778a19 [] NSEC ZSK ECDSAP256SHA256 a09311112cf9138818cd2feae970ebbd 4d6a30f6088c25b325a39abbc5cd1197 aa098283e5aaf421177c2aa5d714992a 9957d1bcc18f98cd71f1f1806b65e148 [] SOA anuj.ns.cloudflare.com 172.64.33.65 [] SOA anuj.ns.cloudflare.com 173.245.59.65 [] SOA anuj.ns.cloudflare.com 108.162.193.65 [] SOA anuj.ns.cloudflare.com 2a06:98c1:50::ac40:2141 [] SOA anuj.ns.cloudflare.com 2606:4700:58::adf5:3b41 [] SOA anuj.ns.cloudflare.com 2803:f800:50::6ca2:c141 [] NS rose.ns.cloudflare.com 172.64.32.141 [] Bind Version for 172.64.32.141 "2024.5.2" [] NS rose.ns.cloudflare.com 108.162.192.141 [] Bind Version for 108.162.192.141 "2024.5.2" [] NS rose.ns.cloudflare.com 173.245.58.141 [] Bind Version for 173.245.58.141 "2024.5.2" [] NS rose.ns.cloudflare.com 2606:4700:50::adf5:3a8d [] Bind Version for 2606:4700:50::adf5:3a8d "2024.5.2" [] NS rose.ns.cloudflare.com 2a06:98c1:50::ac40:208d [] Bind Version for 2a06:98c1:50::ac40:208d "2024.5.2" [] NS rose.ns.cloudflare.com 2803:f800:50::6ca2:c08d [] Bind Version for 2803:f800:50::6ca2:c08d "2024.5.2" [] NS anuj.ns.cloudflare.com 173.245.59.65 [] Bind Version for 173.245.59.65 "2024.5.2" [] NS anuj.ns.cloudflare.com 108.162.193.65 [] Bind Version for 108.162.193.65 "2024.5.2" [] NS anuj.ns.cloudflare.com 172.64.33.65 [] Bind Version for 172.64.33.65 "2024.5.2" [] NS anuj.ns.cloudflare.com 2a06:98c1:50::ac40:2141 [] Bind Version for 2a06:98c1:50::ac40:2141 "2024.5.2" [] NS anuj.ns.cloudflare.com 2606:4700:58::adf5:3b41 [] Bind Version for 2606:4700:58::adf5:3b41 "2024.5.2" [] NS anuj.ns.cloudflare.com 2803:f800:50::6ca2:c141 [] Bind Version for 2803:f800:50::6ca2:c141 "2024.5.2" [] MX goodmanre-com.mail.protection.outlook.com 52.101.42.16 [] MX goodmanre-com.mail.protection.outlook.com 52.101.194.0 [] MX goodmanre-com.mail.protection.outlook.com 52.101.42.9 [] MX goodmanre-com.mail.protection.outlook.com 52.101.8.32 [] MX goodmanre-com.mail.protection.outlook.com 52.101.10.10 [] MX goodmanre-com.mail.protection.outlook.com 52.101.194.19 [] MX goodmanre-com.mail.protection.outlook.com 52.101.10.8 [] A goodmanre.com 208.113.239.178 [] TXT goodmanre.com MS=ms15903347 [] TXT goodmanre.com google-site-verification=tDcgZriVuP0v5ueFsPACgIPOaKFuU6s1kX78Umi6P3g [] TXT goodmanre.com v=spf1 include:spf.protection.outlook.com include:asp-spf1.yardi.com include:asp-spf2.yardi.com -all [] TXT goodmanre.com A2xkfSHJms5QADcSRK+FRDI09m62VrtfQvEp7d0A2YpVuk8i1xsCokTiC3JkU37J9XRpXarPh34ADVaeFNoYoA== [] TXT _dmarc.goodmanre.com v=DMARC1; p=quarantine; rua=mailto:paulfi@goodmanre.com [] TXT _domainkey.goodmanre.com o=~; [] Enumerating SRV Records [+] SRV _sipfederationtls._tcp.goodmanre.com sipfed.online.lync.com 52.114.159.167 5061 [+] 1 Records Found

Here's the result of Cloudfail:


/ | | | | | () | | | | |/ | | | |/ | |_ / _ | | | | || | () | || | (| | | (| | | | \||\/ _,|_,|| _,||_| v1.0.5 by m0rtem

[04:16:06] Initializing CloudFail - the date is: 10/05/2024
[04:16:06] Fetching initial information from: goodmanre.com...
[04:16:06] Server IP: 208.113.239.178
[04:16:06] Testing if goodmanre.com is on the Cloudflare network...
[04:16:06] goodmanre.com is not part of the Cloudflare network, quitting...