?
Solved

detect dns server

Posted on 2013-01-06
2
Medium Priority
?
317 Views
Last Modified: 2013-01-10
sounds like a strange question, but is there a way to detect all dns servers on our internal network?
0
Comment
Question by:al4629740
2 Comments
 
LVL 9

Accepted Solution

by:
gt2847c earned 1600 total points
ID: 38749548
Several possible ways to discover active servers, not necessarily all of them (especially if someone is attempting to conceal them)...

Cisco and other enterprise class network equipment support netflow collection.  Using netflow data you can look for traffic on TCP and UDP port 53.  Any internal network address answering traffic on 53 will likely be a DNS server or doing something it isn't supposed to which is still interesting.

Placing a sniffer (Wireshark, TCPDump, etc) in a central network traffic location and mirroring traffic to it can also be used to scan for the same traffic as above.

Actively scanning for systems answering on TCP and/or UDP 53.  NMAP is a free port scan utility that can do this.  There are plenty of commercial offerings as well.  Anything listening (and answering) on 53 is either a DNS server or again doing something it probably shouldn't be...
0
 
LVL 23

Assisted Solution

by:Suliman Abu Kharroub
Suliman Abu Kharroub earned 400 total points
ID: 38752878
0

Featured Post

Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Learn how to PXE Boot both BIOS & UEFI machines with DHCP Policies and Custom Vendor Classes
This applies to Dell but may also apply to other manufacturers as well. We ran across a few machines that just dropped recently it trust relationship with the server. After doing the basic removing and joining the domain again, it changed to No logo…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
This video tutorial shows you the steps to go through to set up what I believe to be the best email app on the android platform to read Exchange mail.  Get the app on your phone: The first step is to make sure you have the Samsung Email app on your …

621 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question