Domain name security test method and device, computer equipment, readable storage medium and program product
Through the analysis and port detection of the enterprise domain name information set, the target address and port pairs of reverse proxy attributes are filtered, and the hidden domain name risks are detected and fixed, which solves the problem of domain names being ignored in enterprise network security and improves the comprehensiveness of network security protection.
Patent Information
- Application Number
- CN202510711006.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2025-07-11
AI Technical Summary
During the development, testing or use of business systems, some domain names are easily ignored in security protection, making it difficult to achieve comprehensive protection of network security.
By obtaining the domain name information set of objects to be checked, domain name resolution and port detection are performed, target address port pairs of reverse proxy attributes are filtered, access requests are sent to detect hidden domain name risks, and extended domain name testing is carried out based on the domain name removal information and preset subdomain name sets of authoritative DNS servers to identify and fix security risks.
It improves the efficiency of detecting external network exposure risks for unresolved domain names, can identify and repair hidden domain names with security risks, and enhances the comprehensiveness of enterprise network security protection.
Smart Images

Figure CN120301701A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular, to a domain name security testing method, apparatus, computer device, computer-readable storage medium, and computer program product. Background Art
[0002] With the development of the Internet, the degree of digitalization and networking of enterprise operations has been continuously improved, and a large number of business systems have been deployed on the Internet. With the continuous expansion of the scale of network assets, enterprises face higher requirements for network security protection.
[0003] Among them, as an important entry for external access, the security of domain names plays a key role in ensuring the network security of enterprises. However, enterprises usually involve a large number of domain names in the development, testing, or use of business systems, and some domain names are easily overlooked in security protection, resulting in difficulty in achieving comprehensive protection of network security. Summary of the Invention
[0004] Based on this, in view of the above technical problems, it is necessary to provide a domain name security testing method, apparatus, computer device, computer-readable storage medium, and computer program product.
[0005] In a first aspect, the present application provides a domain name security testing method, including:
[0006] Obtain a domain name information set of an object to be checked;
[0007] Perform domain name resolution on each domain name information in the domain name information set to obtain a candidate address set of the object to be checked and determine unresolved domain names in the domain name information set;
[0008] Perform port probing operations on each address identifier in the candidate address set to obtain port probing results;
[0009] According to the port probing results, filter target address-port pairs for providing Hypertext Transfer Protocol or Secure Hypertext Transfer Protocol services, and determine whether each of the target address-port pairs has a reverse proxy attribute;
[0010] According to the access priorities of each of the target address-port pairs, sequentially send access requests containing the unresolved domain names to each of the target address-port pairs; among them, the target address-port pairs with reverse proxy attributes have higher access priorities;
[0011] If valid response information is received from the target address-port pair, obtain hidden domain name risk information of the object to be checked according to the unresolved domain name and the target address-port pair; the hidden domain name risk information is used for the object to be checked to perform domain name security repair.
[0012] In one embodiment, the method further includes: obtaining a removed domain name according to the domain name removal information of the object to be queried in the authoritative domain name system; sequentially sending access requests including the removed domain name to each of the target address-port pairs according to the access priorities of the target address-port pairs; if valid response information is received from the target address-port pair, obtaining the hidden domain name risk information of the object to be queried according to the removed domain name and the target address-port pair.
[0013] In one embodiment, the method further includes: constructing an extended domain name of the object to be queried according to a preset sub-domain name set; sequentially sending access requests including the extended domain name to each of the target address-port pairs according to the access priorities of the target address-port pairs; if valid response information is received from the target address-port pair, obtaining the hidden domain name risk information of the object to be queried according to the extended domain name and the target address-port pair.
[0014] In one embodiment, the performing domain name resolution on each domain name information in the domain name information set to obtain multiple candidate address identifiers of the object to be queried includes:
[0015] Performing domain name resolution on each domain name information in the domain name information set to obtain a first address identifier corresponding to each resolvable domain name in the domain name information set;
[0016] If there are a number of the first address identifiers not less than a preset threshold corresponding to the same address segment, obtaining a second address identifier according to each address identifier in the address segment except the first address identifier;
[0017] Obtaining the candidate address set according to the first address identifier and the second address identifier.
[0018] In one embodiment, before sequentially sending access requests including the unresolved domain name to each of the target address-port pairs, it includes:
[0019] Determining a first access priority for each of the target address-port pairs according to whether the target address-port pair has a reverse proxy attribute; wherein, the target address-port pair with the reverse proxy attribute has a higher first access priority;
[0020] Among the target address-port pairs corresponding to the same first access priority, determining a second access priority for each of the target address-port pairs according to the address identifier included in each of the target address-port pairs; wherein, the target address-port pair with the address identifier being the first address identifier has a higher second access priority;
[0021] Based on the first access priority and the second access priority of each of the target address - port pairs, obtain the access priority of each of the target address - port pairs.
[0022] In one embodiment, the obtaining the domain name information set of the object to be checked includes: obtaining the main domain name of the object to be checked; performing a sub - domain name enumeration operation on the main domain name to obtain a sub - domain name enumeration result; using a preset search engine to search for sub - domain names of the main domain name to obtain a sub - domain name search result; querying for sub - domain names associated with the certificate information of the main domain name to obtain a sub - domain name association result; matching the main domain name with the domain name access record of the object to be checked to obtain a sub - domain name access result; matching the main domain name with the domain name query record of the internal domain name system of the object to be checked to obtain a sub - domain name query result; and obtaining the domain name information set according to the main domain name, the sub - domain name enumeration result, the sub - domain name search result, the sub - domain name association result, the sub - domain name access result, and the sub - domain name query result.
[0023] In a second aspect, the present application further provides a domain name security testing device, including:
[0024] A domain name acquisition module, configured to acquire the domain name information set of the object to be checked;
[0025] A domain name resolution module, configured to perform domain name resolution on each domain name information in the domain name information set to obtain a candidate address set of the object to be checked and determine the un - resolved domain names in the domain name information set;
[0026] A port detection module, configured to perform port detection operations on each address identifier in the candidate address set to obtain a port detection result;
[0027] A result processing module, configured to filter out target address - port pairs for providing Hypertext Transfer Protocol or Secure Hypertext Transfer Protocol services according to the port detection result, and determine whether each of the target address - port pairs has a reverse proxy attribute;
[0028] A domain name testing module, configured to sequentially send access requests containing the un - resolved domain names to each of the target address - port pairs according to the access priority of each of the target address - port pairs; wherein, the target address - port pairs with reverse proxy attributes have a higher access priority;
[0029] A risk information acquisition module, configured to, if valid response information is received from the target address - port pair, obtain the hidden domain name risk information of the object to be checked according to the un - resolved domain name and the target address - port pair; the hidden domain name risk information is used for domain name security repair of the object to be checked.
[0030] In a third aspect, the present application further provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0031] Obtain a domain name information set of the object to be queried;
[0032] Perform domain name resolution on each domain name information in the domain name information set to obtain a candidate address set of the object to be queried and determine the unresolved domain names in the domain name information set;
[0033] Perform port detection operations on each address identifier in the candidate address set to obtain port detection results;
[0034] According to the port detection results, filter out target address - port pairs for providing Hypertext Transfer Protocol or Secure Hypertext Transfer Protocol services, and determine whether each of the target address - port pairs has a reverse proxy attribute;
[0035] According to the access priorities of each of the target address - port pairs, sequentially send access requests containing the unresolved domain names to each of the target address - port pairs; among them, the target address - port pairs with reverse proxy attributes have higher access priorities;
[0036] If valid response information is received from the target address - port pair, obtain hidden domain name risk information of the object to be queried according to the unresolved domain name and the target address - port pair; the hidden domain name risk information is used for domain name security repair of the object to be queried.
[0037] In a fourth aspect, the present application further provides a computer - readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0038] Obtain a domain name information set of the object to be queried;
[0039] Perform domain name resolution on each domain name information in the domain name information set to obtain a candidate address set of the object to be queried and determine the unresolved domain names in the domain name information set;
[0040] Perform port detection operations on each address identifier in the candidate address set to obtain port detection results;
[0041] According to the port detection results, filter out target address - port pairs for providing Hypertext Transfer Protocol or Secure Hypertext Transfer Protocol services, and determine whether each of the target address - port pairs has a reverse proxy attribute;
[0042] Send access requests containing the unparsed domain name to each of the target address-port pairs in sequence according to the access priority of each target address-port pair; among them, the target address-port pair with reverse proxy attributes has a higher access priority.
[0043] If valid response information is received from the target address-port pair, obtain the hidden domain name risk information of the object to be checked according to the unparsed domain name and the target address-port pair; the hidden domain name risk information is used for domain name security repair of the object to be checked.
[0044] In a fifth aspect, the present application also provides a computer program product, including a computer program, which when executed by a processor implements the following steps:
[0045] Obtain the domain name information set of the object to be checked;
[0046] Perform domain name resolution on each domain name information in the domain name information set to obtain the candidate address set of the object to be checked and determine the unparsed domain name in the domain name information set;
[0047] Perform port probing operations on each address identifier in the candidate address set to obtain port probing results;
[0048] According to the port probing results, filter the target address-port pairs for providing hypertext transfer protocol or secure hypertext transfer protocol services, and determine whether each target address-port pair has reverse proxy attributes;
[0049] Send access requests containing the unparsed domain name to each of the target address-port pairs in sequence according to the access priority of each target address-port pair; among them, the target address-port pair with reverse proxy attributes has a higher access priority.
[0050] If valid response information is received from the target address-port pair, obtain the hidden domain name risk information of the object to be checked according to the unparsed domain name and the target address-port pair; the hidden domain name risk information is used for domain name security repair of the object to be checked.
[0051] The above domain name security testing method, device, computer device, computer-readable storage medium, and computer program product first obtain the domain name information set of the object to be investigated, then perform domain name resolution on each domain name information in the domain name information set to obtain the candidate address set of the object to be investigated and determine the unresolved domain names in the domain name information set. Next, perform port probing operations on each address identifier in the candidate address set to obtain port probing results. Subsequently, screen the target address-port pairs for providing Hypertext Transfer Protocol or Secure Hypertext Transfer Protocol services according to the port probing results and determine whether each target address-port pair has a reverse proxy attribute, and send access requests containing the unresolved domain names to each target address-port pair in turn according to the access priorities of each target address-port pair. Among them, the target address-port pairs with reverse proxy attributes have higher access priorities. If valid response information is received from the target address-port pair, then obtain the hidden domain name risk information of the object to be investigated according to the unresolved domain name and the target address-port pair. This hidden domain name risk information is used for the object to be investigated to perform domain name security repair. In this solution, after obtaining the domain name information set of the object to be investigated, by performing domain name resolution on each domain name information in the domain name information set, it is possible to comprehensively screen the address identifiers of the network assets of the object to be investigated to obtain the candidate address set, and it is also possible to identify and screen the unresolved domain names that fail to resolve to address identifiers. Among them, by performing port probing operations on each address identifier in the candidate address set, it is possible to perform a full-port scan of the network assets of the object to be investigated to comprehensively screen the target address-port pairs with open ports and reverse proxy capabilities. Subsequently, by sending access requests containing unresolved domain names to the target address-port pairs, it is possible to detect the external network exposure risk of the unresolved domain names. And by preferentially accessing the target address-port pairs with reverse proxy attributes, it is possible to improve the detection efficiency of the external network exposure risk of the unresolved domain names. Among them, if the access request containing the unresolved domain name can obtain valid response information from the target address-port pair, it means that this domain name is a hidden domain name with external network exposure risk. Thus, obtaining the hidden domain name risk information according to the unresolved domain name and the corresponding target address-port pair can perform security governance on the hidden domain names with security risks, which is beneficial to improving the comprehensiveness of the network security protection of the object to be investigated. Brief Description of the Drawings
[0052] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for the description of the embodiments of the present application or related technologies. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0053] Figure 1 It is a schematic flowchart of the domain name security testing method in an embodiment;
[0054] Figure 2 It is a schematic flowchart of obtaining hidden domain name risk information in an embodiment;
[0055] Figure 3 It is a schematic flowchart of obtaining hidden domain name risk information in another embodiment;
[0056] Figure 4 It is a schematic flowchart of obtaining candidate address identifiers in an embodiment;
[0057] Figure 5 It is a schematic flowchart of obtaining access priorities of each target address - port pair in an embodiment;
[0058] Figure 6 It is a schematic diagram of the acquisition method of sub - domain names in an embodiment;
[0059] Figure 7 It is a schematic flowchart of a domain name security testing method in another embodiment;
[0060] Figure 8 It is a structural block diagram of a domain name security testing device in an embodiment;
[0061] Figure 9 It is an internal structure diagram of a computer device in an embodiment. Specific implementation manners
[0062] In order to make the purpose, technical solutions and advantages of this application more clear and understandable, the following further elaborates on this application in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit this application.
[0063] Specifically, in the development, testing or use of an enterprise business system, in addition to the externally - exposed domain names, there are also some domain names that are not externally - exposed but are used for internal network access or for development or testing. Among them, when the enterprise is negligent in domain name management, some non - externally - exposed domain names are likely to be exposed to the external network, making the corresponding services and data vulnerable to attacks or leaks. Based on this, this application provides a domain name security testing method. By screening and testing the enterprise's own domain name information, hidden domain names with security risks can be identified and security governance can be carried out on them, which is beneficial to improving the comprehensiveness of the enterprise's network security protection.
[0064] In one embodiment, as Figure 1 shown, a domain name security testing method is provided. In this embodiment, it is exemplified that this method is applied to a server. It can be understood that this method can also be applied to a terminal, and can also be applied to a system including a terminal and a server, and is implemented through the interaction between the terminal and the server. In this embodiment, the method includes the following steps:
[0065] Step S101: Obtain the domain name information set of the object to be queried.
[0066] Specifically, the object to be queried may be a subject that requires network security protection. In the method provided in this application, the collection and detection processes of relevant information such as the domain name, address identifier, and port of the object to be queried are all fully authorized by the object to be queried.
[0067] Among them, the domain name information set of the object to be queried may include multiple domain name information of the object to be queried, and each domain name information may respectively correspond to a relevant domain name of the object to be queried. Exemplarily, the domain name information set may include domain name information corresponding to the main domain name and sub-domain names of the object to be queried, and these domain name information can be collected according to the network public information of the object to be queried (such as official websites, domain name filing information, network search results, etc.) and the internal network information of the object to be queried (such as internal network domain name access records, etc.).
[0068] Step S102: Perform domain name resolution on each domain name information in the domain name information set to obtain the candidate address set of the object to be queried and determine the un-resolved domain names in the domain name information set.
[0069] Among them, for each domain name information in the domain name information set, a DNS query request containing the domain name information can be sent to a Domain Name System (DNS) server (hereinafter referred to as the "DNS server") to perform domain name resolution on the domain name information. Among them, according to the DNS query response received from the DNS server, the Internet Protocol Address (IP address) (hereinafter simply referred to as the "address identifier") corresponding to the domain name information can be obtained, or it can be confirmed that the domain name information cannot be resolved by the corresponding DNS server. Exemplarily, in this step, a script program can be used to perform batch domain name resolution on each domain name information in the domain name information set.
[0070] Among them, the same DNS query request can be sent to multiple different DNS servers (for example, it can include public DNS servers, local Internet service provider DNS servers, etc.) to obtain DNS query responses from different DNS servers. Since different DNS servers may adopt different caching policies, have different network latencies, etc., they may return different DNS query responses. Among them, for the domain name information that can obtain the address identifier through domain name resolution, it can be determined that the domain name information is a resolvable domain name, and the resolvable domain name and its corresponding address identifier are associated and saved. Among them, according to the address identifiers corresponding to the resolvable domain names in the domain name information set, the candidate address set of the object to be queried can be obtained. Among them, for the domain name information that cannot obtain the address identifier through domain name resolution, it can be determined that the domain name information is an unresolved domain name.
[0071] Optionally, the candidate address set of the object to be queried may further include other address identifiers extended from the address identifier obtained by domain name resolution.
[0072] Step S103: Perform port probing operations on each address identifier in the candidate address set to obtain port probing results.
[0073] Step S104: According to the port probing results, screen out the target address-port pairs for providing HyperText Transfer Protocol or HyperText Transfer Protocol Secure services, and determine whether each target address-port pair has a reverse proxy attribute.
[0074] Among them, in step S103, port probing operations can be performed on each address identifier in the candidate address set respectively to obtain the port probing result corresponding to the address identifier. Then, in step S104, according to the port probing results, the target address-port pairs for providing HyperText Transfer Protocol (HTTP) or HyperText Transfer Protocol Secure (HTTPS) services can be screened out, and it can be determined whether each target address-port pair has a reverse proxy attribute.
[0075] Exemplarily, the port probing operation performed on the address identifier may be a full port scan of the address identifier to filter out all open ports that provide HyperText Transfer Protocol (HTTP) or HyperText Transfer Protocol Secure (HTTPS) services for the address identifier, and obtain the port probing result of the address identifier based on the response information returned by each open port. Among them, the response information of each open port may include the service identifier information of the service software it provides. For example, it may be through the service field (such as the Server field) in the response header, or the specific structured tag content included in the response body (such as <title>、< / title> <center>etc.), service identification information is obtained. Among them, if the service software corresponding to the service identification information of the open port has reverse proxy capabilities, it can be determined that the open port has reverse proxy attributes; otherwise, it can be determined that the open port does not have reverse proxy attributes.
[0076] Exemplarily, for the port probing operation on the address identification, in addition to performing a full-port scan on the address identification itself, a full-port scan can also be combined with the address identification and the resolvable domain name corresponding to the address identification, and then the port probing result of the address identification can be obtained according to the response information returned by each open port in each scan.
[0077] Exemplarily, after screening out the target address-port pairs and determining whether each target address-port pair has reverse proxy attributes, information such as the protocol services (HTTP / HTTPS) provided by each target address-port pair, the corresponding address identification, port, and whether it has reverse proxy attributes can be associated and stored. Exemplarily, when the candidate address set includes the extended address identification, information such as the protocol services provided by each target address-port pair, the corresponding address identification, port, whether it has reverse proxy attributes, and whether it is an extended address identification can be associated and stored.
[0078] Step S105, according to the access priorities of each target address-port pair, send access requests containing unparsed domain names to each target address-port pair in sequence.
[0079] In this step, the unparsed domain names can be tested by means of HOST collision. For each unparsed domain name, an access request with the domain name as the host header field can be constructed, and according to the access priorities of each target address-port pair, the constructed access requests are sent to each target address-port pair in sequence. Among them, the access request can include HTTP requests and HTTPS requests, and when sending, an HTTP request or an HTTPS request can be sent according to the protocol service type provided by the target address-port pair.
[0080] Among them, when the target address-port pair is configured with virtual host or routing information corresponding to the unparsed domain name, and the target address-port pair trusts the unparsed domain name or does not perform verification on the host header field, etc., the target address-port pair can return valid response information (such as business data corresponding to the unparsed domain name, etc.) after receiving the access request; while in the case where the target address-port pair is not configured with a virtual host corresponding to the unparsed domain name, or the unparsed domain name is not in the trust list of the target address-port pair, etc., the target address-port pair can return an error message after receiving the access request.
[0081] Among them, the access priority of each target address - port pair can be determined according to whether it has the reverse - proxy attribute. The access priority of the target address - port pair with the reverse - proxy attribute is higher than that of the target address - port pair without the reverse - proxy attribute. In this step, access requests containing the unresolved domain name can be sent to each target address - port pair in turn according to the access priority of each target address - port pair. When valid response information is received from a target address - port pair, the sending of access requests to the next target address - port pair can be stopped, and the process can proceed to step S106.
[0082] It can be understood that when the target address - port pair has the reverse - proxy attribute and stores configuration information corresponding to the unresolved domain name, after receiving the access request, the target address - port pair will forward the received request to the internal business server corresponding to the unresolved domain name in the local area network according to this configuration information, and then return the corresponding valid response information. Among them, for some domain names that are not open to the outside world, during development or testing, the corresponding reverse - proxy configuration information may be set and not deleted in time, resulting in the attack or leakage of the business that should have been hidden. At the same time, reverse proxy usually supports multiple host configurations. Based on this, by setting a higher access priority for the target address - port pair with the reverse - proxy attribute, the detection efficiency of hidden domain names with security risks can be improved.
[0083] Step S106: If valid response information is received from the target address - port pair, obtain the hidden - domain - name risk information of the object to be checked according to the unresolved domain name and the target address - port pair. The hidden - domain - name risk information is used for the object to be checked to perform domain - name security repair.
[0084] Among them, after sending an access request containing the unresolved domain name to a certain target address - port pair, if valid response information is received from the target address - port pair, it can be determined that the target address - port pair stores configuration information corresponding to the unresolved domain name. In this case, potential attackers can access the hidden business data of the object to be checked through the external network by modifying the host - header field of the access request or the local - host mapping file (hosts file).
[0085] Therefore, in this step, after receiving the valid response information from the target address - port pair, the hidden - domain - name risk information of the object to be checked can be obtained according to the corresponding unresolved domain name and the target address - port pair. Among them, according to the hidden - domain - name risk information, domain - name security repair can be carried out by modifying the configuration information or verification mechanism of the corresponding target address - port pair, etc., so as to reduce the exposure surface of the object to be checked.
[0086] In the above domain name security testing method, after obtaining the domain name information set of the object to be checked, by performing domain name resolution on each domain name information in the domain name information set, the address identifier of the network asset of the object to be checked can be comprehensively screened to obtain a candidate address set, and the unresolved domain name that cannot be resolved to the address identifier can be identified and screened. Among them, by performing port detection operations on each address identifier in the candidate address set, the network asset of the object to be checked can be fully scanned to comprehensively screen the target address port pairs with open ports and reverse proxy capabilities. Subsequently, by sending an access request containing an unresolved domain name to the target address port pair, the external network exposure risk of the uninterpreted domain name can be detected, and by preferentially accessing the target address port pair with reverse proxy attributes, the detection efficiency of the external network exposure risk of the uninterpreted domain name can be improved. Among them, if the access request containing the unresolved domain name can obtain valid response information from the target address port pair, it means that the domain name is a hidden domain name with an external network exposure risk, so that the hidden domain name risk information is obtained according to the unresolved domain name and the corresponding target address port pair, and the hidden domain name with security risks can be managed securely, which is conducive to improving the comprehensiveness of the network security protection of the object to be checked.
[0087] In an exemplary embodiment, Figure 2 As shown, the method may also include:
[0088] Step S201, obtaining a removed domain name according to the domain name removal information of the object to be checked in the authoritative domain name system.
[0089] Step S202: sending access requests containing the removed domain names to each target address-port pair in sequence according to the access priority of each target address-port pair.
[0090] Step S203: If valid response information is received from the target address-port pair, the hidden domain name risk information of the object to be checked is obtained according to the removed domain name and the target address-port pair.
[0091] Specifically, an authoritative domain name system server (hereinafter referred to as "authoritative DNS server") is a server used to manage specific domain name resolution records, which stores mapping information from domain names to address identifiers (IP addresses). Among them, the authoritative DNS server is usually specified by the domain name holder, and only the domain name holder can change the corresponding domain name resolution record. Among them, when a class A record or a class AAAA record in an authoritative DNS server is deleted, it means that the domain name holder does not want the domain name related to the record to be exposed to the external network. Based on this, in this embodiment, a security check can be performed on the domain name of the object to be checked that has been removed from the authoritative DNS server.
[0092] Among them, in step S201, the domain name removal information of the object to be investigated in the authoritative DNS server can be obtained. Exemplarily, when the authoritative DNS server is maintained by the object to be investigated or the authorizer of the object to be investigated, a proxy service (Agent) can be deployed on the server to continuously monitor the change of the domain name resolution record of the object to be investigated. When it is detected that the A record or AAAA record of the object to be investigated is deleted, the domain name removal information of the object to be investigated can be obtained. Among them, the domain name removal information may include the domain name information of the removed domain name corresponding to the removed record. Exemplarily, when the authoritative DNS server is maintained by a third party, the domain name removal information of the object to be investigated in the authoritative DNS server can be obtained according to the domain name maintenance record of the object to be investigated. Optionally, after obtaining the domain name removal information, relevant sub-domains can be further expanded based on the removed domain name included in the domain name removal information and added as the removed domain name.
[0093] Among them, in step S202, an access request with the removed domain name as the host header field can be constructed, and the constructed access request is sequentially sent to each target address-port pair according to the access priority of each target address-port pair. Then, in step S203, after receiving the valid response information from the target address-port pair, the hidden domain name risk information of the object to be investigated can be obtained according to the corresponding removed domain name and the target address-port pair. The specific implementation manners of step S202 and step S203 are similar to the foregoing steps S105 to S106, and will not be elaborated here.
[0094] In this embodiment, the change situation of the domain name resolution record in the authoritative DNS server is taken into consideration. By obtaining the domain name removal information of the authoritative DNS server, the removed domain name that the object to be investigated hopes to hide or protect can be determined. Then, by using the removed domain name for HOST collision, the hidden domain name that the object to be investigated fails to successfully recycle can be discovered in time, which is beneficial to further reducing the exposure surface of the object to be investigated and improving network security.
[0095] In an exemplary embodiment, as Figure 3 shown, the method may further include:
[0096] Step S301, constructing an extended domain name of the object to be investigated according to a preset sub-domain name set.
[0097] Specifically, in addition to the unresolved domain names screened from the domain name information set, in this embodiment, the domain names that the object to be investigated may be associated with can be further extended and tested according to the preset sub-domain name set.
[0098] In this step, the extended domain name of the object to be queried can be constructed according to a preset sub-domain name set. The preset sub-domain name set can include common intranet sub-domain names, such as hr, sso, crm, etc. In this step, each sub-domain name in the preset sub-domain name set can be concatenated with the main domain name of the object to be queried to obtain the extended domain name of the object to be queried. Optionally, after obtaining the extended domain name, the extended domain name can also be de-duplicated according to the domain name information set to remove the domain names that have been tested.
[0099] Step S302: According to the access priorities of the target address-port pairs, send access requests containing the extended domain name to each target address-port pair in sequence.
[0100] Step S303: If valid response information is received from a target address-port pair, obtain the hidden domain name risk information of the object to be queried based on the extended domain name and the target address-port pair.
[0101] Among them, in step S302, an access request with the extended domain name as the host header field can be constructed, and according to the access priorities of the target address-port pairs, the constructed access request is sent to each target address-port pair in sequence. Then in step S303, after receiving valid response information from a target address-port pair, the hidden domain name risk information of the object to be queried can be obtained according to the corresponding extended domain name and the target address-port pair. The specific implementation manners of step S302 and step S303 are similar to the foregoing steps S105 to S106 and will not be elaborated here.
[0102] In this embodiment, by constructing the extended domain name of the object to be queried according to the preset sub-domain name set and then performing HOST collision on the extended domain name, a more comprehensive detection of hidden domain names that may have security risks can be realized, which is beneficial to further reducing the exposure surface of the object to be queried and improving network security.
[0103] In an exemplary embodiment, as Figure 4 shown, performing domain name resolution on each domain name information in the domain name information set to obtain multiple candidate address identifiers of the object to be queried may include:
[0104] Step S401: Perform domain name resolution on each domain name information in the domain name information set to obtain the first address identifier corresponding to each resolvable domain name in the domain name information set.
[0105] Specifically, in this step, a DNS query request containing domain name information can be sent to a DNS server to perform domain name resolution on the domain name information. Among them, according to the DNS query response received from the DNS server, the first address identifier corresponding to the domain name information can be obtained, or it can be confirmed that the domain name information cannot be resolved by the corresponding DNS server. Exemplarily, in this step, a script program can be used to perform batch domain name resolution on each domain name information in the domain name information set.
[0106] Among them, the same DNS query request can be sent to multiple different DNS servers (for example, it can include a public DNS server, a local Internet service provider DNS server, etc.) to obtain DNS query responses from different DNS servers. Subsequently, according to the DNS query responses of each DNS server, the first address identifier corresponding to each resolvable domain name can be obtained.
[0107] Step S402, if there are a number of first address identifiers not less than a preset threshold corresponding to the same address segment, then according to each address identifier in the address segment except the first address identifier, a second address identifier is obtained.
[0108] Among them, for the first address identifier corresponding to each resolvable domain name, the address segments corresponding to each first address identifier can be counted, and the number of first address identifiers corresponding to each address segment can be obtained. Wherein, the first address identifiers corresponding to the same address segment can mean that the first address identifiers belong to the same C-class address segment.
[0109] Among them, when the number of first address identifiers corresponding to the same address segment is not less than the preset threshold, it can be determined that the address identifiers of the entire address segment may all be used by the object to be investigated. Thus, the address identifiers in the address segment except the first address identifier can be used as the second address identifier of the object to be investigated. Among them, the second address identifier can be the address identifier confirmed to be used by the object to be investigated in this address segment.
[0110] Exemplarily, the preset threshold can be 3. If the resolvable domain names of the object to be investigated, such as www.exple.com, test.exple.com, and test1.exple.com, are respectively resolved to the first address identifiers 10.10.10.1, 10.10.10.100, and 10.10.10.200, then it can be considered that the address identifiers of the entire 10.10.10.1 / 24 C-class address segment may all be used by the object to be investigated. Thus, the other address identifiers in this C-class address segment except the first address identifier can be used as the second address identifier of the object to be investigated. It can be understood that the preset threshold can also be set to other values according to actual needs. It can be understood that the second address identifier can be the address identifier confirmed to be used by the object to be investigated in this C-class address segment.
[0111] Step S403: Obtain a candidate address set based on the first address identifier and the second address identifier.
[0112] Among them, based on the first address identifier and the second address identifier of the object to be queried, a candidate address set of the object to be queried can be obtained.
[0113] In this embodiment, by counting the address segments where the first address identifier is located and expanding the second address identifier according to the address segments with multiple first address identifiers, address identifiers that may be associated with the object to be queried can be collected more comprehensively, which helps to avoid missing hidden domain names that may pose security risks.
[0114] In an exemplary embodiment, as Figure 5 shown, before sequentially sending access requests containing unparsed domain names to each target address-port pair, it may include:
[0115] Step S501: Determine the first access priority of each target address-port pair according to whether the target address-port pair has a reverse proxy attribute.
[0116] Specifically, in this embodiment, the access priority of each target address-port pair can be determined according to whether the target address-port pair has a reverse proxy attribute and the type of the address identifier it contains.
[0117] In this step, the first access priority of each target address-port pair can be set first, where the first access priority of the target address-port pair with a reverse proxy attribute is higher than that of the target address-port pair without a reverse proxy attribute.
[0118] Step S502: Among the target address-port pairs corresponding to the same first access priority, determine the second access priority of each target address-port pair according to the address identifier contained in each target address-port pair.
[0119] In this step, according to the address identifier contained in each target address-port pair, the second access priority can be set for each target address-port pair corresponding to the same first access priority. Among them, when the address identifier contained in the target address-port pair is the first address identifier, its second access priority is higher than that of the target address-port pair whose contained address identifier is the second address identifier.
[0120] Step S503: Obtain the access priority of each target address-port pair according to the first access priority and the second access priority of each target address-port pair.
[0121] Among them, according to the first access priority and the second access priority of each target address-port pair, the access priority of each target address-port pair can be determined. Exemplarily, the target address-port pairs can be sorted according to the first access priority first, and then the target address-port pairs belonging to the same first access priority can be sorted according to the second access priority to obtain the access priority of each target address-port pair. Exemplarily, the access priority of each target address-port pair can be as shown in Table 1:
[0122] Table 1
[0123]
[0124] Among them, the access priority of each target address-port pair can decrease as the corresponding access priority order increases.
[0125] In this embodiment, by first setting the first priority according to whether the target address-port pair has a reverse proxy attribute, then determining the second priority according to whether its corresponding first address identifier is obtained by domain name information resolution or the second address identifier obtained by address segment expansion, and finally obtaining the access priority of the target address-port pair according to the first priority and the second priority, it is possible to preferentially perform access tests on the target address-port pairs that have the reverse proxy attribute and are determined to correspond to the object to be investigated in the subsequent collision test, which is beneficial to improving the efficiency of discovering hidden domain names with security risks.
[0126] In an exemplary embodiment, obtaining the domain name information set of the object to be investigated may include: obtaining the main domain name of the object to be investigated; performing a subdomain enumeration operation on the main domain name to obtain a subdomain enumeration result; using a preset search engine to search for subdomains of the main domain name to obtain a subdomain search result; querying subdomains associated with the certificate information of the main domain name to obtain a subdomain association result; matching the main domain name with the domain name access record of the object to be investigated to obtain a subdomain access result; matching the main domain name with the domain name query record of the internal domain name system of the object to be investigated to obtain a subdomain query result; and obtaining the domain name information set according to the main domain name, the subdomain enumeration result, the subdomain search result, the subdomain association result, the subdomain access result, and the subdomain query result.
[0127] Specifically, in this embodiment, the domain name information of the object to be investigated can be collected in multiple ways to obtain the domain name information set of the object to be investigated.
[0128] Among them, the main domain name of the object to be queried can be obtained first. Exemplarily, by accessing the official website of the object to be queried, the full name of the object to be queried and the official website domain name can be obtained, and then the full name of the object to be queried can be used to search in the domain name information filing management system to obtain the domain name filing information and address identifier filing information of the object to be queried. Thus, based on the official website domain name and domain name filing information of the object to be queried, one or more main domain names of the object to be queried can be obtained.
[0129] Then, based on the main domain name of the object to be queried, the sub-domains of the object to be queried can be obtained in various ways. Exemplarily, as Figure 6 shown, the collection of sub-domains can be carried out respectively through methods or tools such as sub-domain enumeration, search engines, certificate association, security devices, internal DNS servers, etc.
[0130] Among them, through the operation of sub-domain enumeration on the main domain name, a sub-domain enumeration tool can be used to collect sub-domains related to the main domain name in the public data source, or actively detect the sub-domains related to the main domain name, so as to obtain the sub-domain enumeration result of the object to be queried.
[0131] Among them, by using a preset search engine, the supported domain name retrieval syntax (such as site:exple.com) can be used to search for sub-domains under the main domain name to obtain the sub-domain search result of the object to be queried. Exemplarily, the preset search engine can include general search engines and cyberspace search engines.
[0132] Among them, by querying the certificate transparency log of the main domain name, certificate records matching the main domain name can be obtained, and then the sub-domains associated with the main domain name can be extracted from them to obtain the sub-domain association result of the object to be queried.
[0133] Among them, the object to be queried can deploy security protection and monitoring devices (i.e., "security devices") in the enterprise network environment. Among them, security devices such as full traffic analysis devices can have the ability to collect and record domain name access behaviors and obtain domain name access records in the full traffic. Among them, by removing duplicates from the domain name access records and then comparing each domain name with the main domain name of the object to be queried, it can be determined whether the domain name is a sub-domain of the object to be queried. Thus, by matching the main domain name with the domain name access records, the sub-domain access result of the object to be queried can be obtained.
[0134] Among them, the object to be queried can deploy an internal domain name system (i.e., "internal DNS server") in its internal network to resolve and manage internal domain names. Therefore, the domain name query records stored in the internal DNS server can be matched with the main domain name of the object to be queried, and the sub-domains associated with the object to be queried can be screened out from them to obtain the sub-domain query result.
[0135] Among them, after obtaining the main domain name, sub-domain name enumeration results, sub-domain name search results, sub-domain name association results, sub-domain name access results, and sub-domain name query results, duplicate removal processing can be performed on each domain name information first, and then a domain name information set containing multiple domain name information of the object to be investigated can be obtained.
[0136] In this embodiment, by collecting domain name information based on the public information of the object to be investigated and the internal network data, it is possible to combine the perspective of the attacker and make full use of the enterprise's own data for domain name discovery, which can improve the comprehensiveness of the collected domain name information and help reduce the risk of missing hidden domain names with security risks.
[0137] In an exemplary embodiment, as Figure 7 shown, a domain name security testing method is provided, including the following steps:
[0138] Step S701, collect relevant domain names of the object to be investigated through various methods to obtain a domain name information set. Among them, the main domain name of the object to be investigated can be obtained first, and then sub-domain names can be collected through methods or tools such as sub-domain name enumeration, search engines, certificate association, security devices, and internal DNS servers.
[0139] Step S702, query multiple DNS resolution servers, perform domain name resolution on each domain name information in the domain name information set, collect resolvable domain names and the first address identifiers, and determine unresolvable domain names. Among them, the DNS servers queried can include but are not limited to public DNS servers, local Internet service provider DNS servers, etc.
[0140] Step S703, expand the address segment of the first address identifier to obtain a second address identifier, and obtain a candidate address set according to the first address identifier and the second address identifier. Among them, in the case where the number of first address identifiers corresponding to the same address segment is not less than a preset threshold, the second address identifier can be obtained according to each address identifier in the address segment except the first address identifier, and the address segment can be a C-class address segment.
[0141] Step S704, perform a port probing operation on the first address identifier, resolvable domain name, and second address identifier to obtain a port probing result, identify the target address port pairs with open HTTP and HTTPS according to the port probing result, and determine whether each target address port pair has a reverse proxy attribute. Among them, the port probing operation can be a full port scan.
[0142] Step S705: According to the access priorities of each target address - port pair, send access requests containing un - resolved domain names to each target address - port pair in sequence. When valid response information is received from a target address - port pair, obtain the hidden - domain - name risk information of the object to be investigated. Among them, the un - resolved domain names can be tested by means of HOST collision. Among them, Host collision can be performed periodically or temporarily as needed to promptly discover the latest hidden domain names.
[0143] Step S706: When the domain - name resolution record of the authoritative DNS server is deleted, re - verify whether there is hidden - domain - name risk information related to the removed domain name.
[0144] This embodiment can achieve the following beneficial effects:
[0145] 1. In the domain - name collection stage, not only use external public data for domain - name collection, but also make full use of internal data of security devices, internal DNS servers, etc. deployed by the object to be investigated for domain - name discovery, which is conducive to obtaining a more comprehensive domain - name list.
[0146] 2. In the domain - name test, HOST collision is performed on all ports with open WEB services, which can avoid the problem of missing hidden domain names with security risks that may occur when colliding with common ports such as 80 and 443.
[0147] 3. By identifying whether the address identifier and port have the reverse - proxy attribute, and then setting the access priorities for the target address - port pairs to be collided according to whether they have the reverse - proxy attribute and whether the address identifier is the second address identifier obtained by expansion, hidden domain names with security risks can be discovered more quickly.
[0148] 4. Taking into account the deletion of the domain - name resolution record of the authoritative DNS server, hidden domain names related to domain - name removal information can be discovered in a timely manner.
[0149] It should be understood that although the steps in the flowcharts involved in the above - mentioned embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least some of the steps in the flowcharts involved in the above - mentioned embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment, but can be executed at different moments, and the execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0150] Based on the same inventive concept, an embodiment of this application also provides a domain name security testing device for implementing the domain name security testing method involved above. The implementation solution provided by this device to solve the problem is similar to the implementation solution recorded in the above method. Therefore, the specific limitations in one or more embodiments of the domain name security testing device provided below can refer to the limitations on the domain name security testing method in the above text, and will not be repeated here.
[0151] In an exemplary embodiment, as Figure 8 shown, a domain name security testing device 800 is provided, including:
[0152] A domain name acquisition module 801, configured to acquire a domain name information set of an object to be queried;
[0153] A domain name resolution module 802, configured to perform domain name resolution on each domain name information in the domain name information set to obtain a candidate address set of the object to be queried and determine unresolved domain names in the domain name information set;
[0154] A port detection module 803, configured to perform port detection operations on each address identifier in the candidate address set to obtain port detection results;
[0155] A result processing module 804, configured to screen target address-port pairs for providing Hypertext Transfer Protocol or Secure Hypertext Transfer Protocol services according to the port detection results, and determine whether each of the target address-port pairs has a reverse proxy attribute;
[0156] A domain name testing module 805, configured to sequentially send access requests containing the unresolved domain names to each of the target address-port pairs according to the access priorities of each of the target address-port pairs; among them, the target address-port pairs with reverse proxy attributes have higher access priorities;
[0157] A risk information acquisition module 806, configured to, if valid response information is received from the target address-port pair, obtain hidden domain name risk information of the object to be queried according to the unresolved domain name and the target address-port pair; the hidden domain name risk information is used for domain name security repair of the object to be queried.
[0158] In an exemplary embodiment, the apparatus further includes: a removed domain name acquisition module, configured to obtain a removed domain name according to domain name removal information of the object to be queried in the authoritative domain name system; a removed domain name testing module, configured to sequentially send access requests including the removed domain name to each of the target address-port pairs according to the access priorities of the target address-port pairs; and a risk information acquisition module 806, further configured to, if valid response information is received from the target address-port pair, obtain hidden domain name risk information of the object to be queried according to the removed domain name and the target address-port pair.
[0159] In an exemplary embodiment, the apparatus further includes: an extended domain name acquisition module, configured to construct an extended domain name of the object to be queried according to a preset sub-domain name set; an extended domain name testing module, configured to sequentially send access requests including the extended domain name to each of the target address-port pairs according to the access priorities of the target address-port pairs; and a risk information acquisition module 806, further configured to, if valid response information is received from the target address-port pair, obtain hidden domain name risk information of the object to be queried according to the extended domain name and the target address-port pair.
[0160] In an exemplary embodiment, a domain name resolution module 802 is configured to: perform domain name resolution on each piece of domain name information in the domain name information set to obtain a first address identifier corresponding to each resolvable domain name in the domain name information set; if there are a number of the first address identifiers not less than a preset threshold corresponding to the same address segment, obtain a second address identifier according to the address identifiers in the address segment other than the first address identifier; and obtain the candidate address set according to the first address identifier and the second address identifier.
[0161] In an exemplary embodiment, the apparatus further includes: a first priority determination module, configured to determine a first access priority of each of the target address-port pairs according to whether the target address-port pair has a reverse proxy attribute; wherein, the target address-port pair having the reverse proxy attribute has a higher first access priority; a second priority determination module, configured to determine a second access priority of each of the target address-port pairs according to the address identifiers included in the target address-port pairs corresponding to the same first access priority; wherein, the target address-port pair with the address identifier being the first address identifier has a higher second access priority; and an access priority determination module, configured to obtain the access priority of each of the target address-port pairs according to the first access priority and the second access priority of each of the target address-port pairs.
[0162] In an exemplary embodiment, a domain name acquisition module 801 is configured to: acquire the main domain name of the object to be queried; perform a sub-domain name enumeration operation on the main domain name to obtain a sub-domain name enumeration result; use a preset search engine to search for sub-domain names of the main domain name to obtain a sub-domain name search result; query sub-domain names associated with the certificate information of the main domain name to obtain a sub-domain name association result; match the main domain name with the domain name access record of the object to be queried to obtain a sub-domain name access result; match the main domain name with the domain name query record of the internal domain name system of the object to be queried to obtain a sub-domain name query result; and obtain the domain name information set according to the main domain name, the sub-domain name enumeration result, the sub-domain name search result, the sub-domain name association result, the sub-domain name access result, and the sub-domain name query result.
[0163] Each module in the above domain name security testing device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in or independent of a processor in a computer device in the form of hardware, or stored in a memory in a computer device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.
[0164] In an exemplary embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 9 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data such as the domain name information set of the object to be queried. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a domain name security testing method.
[0165] Those skilled in the art can understand that Figure 9 the structure shown in
[0166] In one embodiment, a computer device is further provided, which includes a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the foregoing method embodiments are implemented.
[0167] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the foregoing method embodiments are implemented.
[0168] In one embodiment, a computer program product is provided, which includes a computer program. When the computer program is executed by a processor, the steps in the foregoing method embodiments are implemented.
[0169] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.
[0170] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.
[0171] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope recorded in the present application.
[0172] The above embodiments only illustrate several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.< / center>
Claims
1. A domain name security testing method, characterized in that, The method includes: Obtaining a domain name information set of an object to be queried; Performing domain name resolution on each domain name information in the domain name information set to obtain a candidate address set of the object to be queried and determining unresolved domain names in the domain name information set; Performing port probing operations on each address identifier in the candidate address set to obtain port probing results; According to the port probing results, screening target address-port pairs for providing Hypertext Transfer Protocol or Secure Hypertext Transfer Protocol services, and determining whether each of the target address-port pairs has a reverse proxy attribute; According to the access priorities of each of the target address-port pairs, sequentially sending access requests containing the unresolved domain names to each of the target address-port pairs; wherein, the target address-port pairs with reverse proxy attributes have higher access priorities; If valid response information is received from the target address-port pair, obtaining hidden domain name risk information of the object to be queried according to the unresolved domain name and the target address-port pair; the hidden domain name risk information is used for domain name security repair of the object to be queried.
2. The method according to claim 1, wherein The method further includes: Obtaining removed domain names according to domain name removal information of the object to be queried in the authoritative domain name system; According to the access priorities of each of the target address-port pairs, sequentially sending access requests containing the removed domain names to each of the target address-port pairs; If valid response information is received from the target address-port pair, obtaining hidden domain name risk information of the object to be queried according to the removed domain name and the target address-port pair.
3. The method according to claim 1, characterized in that, The method further includes: Constructing an extended domain name of the object to be queried according to a preset sub-domain name set; According to the access priorities of each of the target address-port pairs, sequentially sending access requests containing the extended domain name to each of the target address-port pairs; If valid response information is received from the target address-port pair, obtaining hidden domain name risk information of the object to be queried according to the extended domain name and the target address-port pair.
4. The method according to claim 1, characterized in that The performing domain name resolution on each domain name information in the domain name information set to obtain multiple candidate address identifiers of the object to be queried includes: Performing domain name resolution on each domain name information in the domain name information set to obtain first address identifiers corresponding to each resolvable domain name in the domain name information set; If there are a number of the first address identifiers not less than a preset threshold corresponding to the same address segment, obtaining second address identifiers according to the address identifiers in the address segment other than the first address identifiers; Obtaining the candidate address set according to the first address identifiers and the second address identifiers.
5. The method according to claim 4, wherein Before sequentially sending access requests containing the unresolved domain names to each of the target address-port pairs, it includes: Determining a first access priority of each of the target address-port pairs according to whether the target address-port pair has a reverse proxy attribute; wherein, the target address-port pairs with reverse proxy attributes have higher first access priorities; Among the target address - port pairs corresponding to the same first access priority, determine the second access priority of each target address - port pair according to the address identifier included in each target address - port pair; wherein, the target address - port pair with the address identifier being the first address identifier has a higher second access priority. According to the first access priority and the second access priority of each target address - port pair, obtain the access priority of each target address - port pair.
6. The method according to claim 1, wherein The obtaining of the domain name information set of the object to be queried includes: Obtain the main domain name of the object to be queried. Perform a sub - domain name enumeration operation on the main domain name to obtain a sub - domain name enumeration result. Use a preset search engine to search for sub - domain names of the main domain name to obtain a sub - domain name search result. Query the sub - domain names associated with the certificate information of the main domain name to obtain a sub - domain name association result. Match the main domain name with the domain name access record of the object to be queried to obtain a sub - domain name access result. Match the main domain name with the domain name query record of the internal domain name system of the object to be queried to obtain a sub - domain name query result. According to the main domain name, the sub - domain name enumeration result, the sub - domain name search result, the sub - domain name association result, the sub - domain name access result and the sub - domain name query result, obtain the domain name information set.
7. A domain name security testing device, characterized in that, The device includes: A domain name acquisition module, configured to acquire the domain name information set of the object to be queried. A domain name resolution module, configured to perform domain name resolution on each domain name information in the domain name information set to obtain the candidate address set of the object to be queried and determine the un - resolved domain names in the domain name information set. A port detection module, configured to perform a port detection operation on each address identifier in the candidate address set to obtain a port detection result. A result processing module, configured to screen the target address - port pairs for providing hyper - text transfer protocol or secure hyper - text transfer protocol services according to the port detection result, and determine whether each target address - port pair has a reverse proxy attribute. A domain name testing module, configured to sequentially send access requests containing the un - resolved domain names to each target address - port pair according to the access priority of each target address - port pair; wherein, the target address - port pair with a reverse proxy attribute has a higher access priority. A risk information acquisition module, configured to, if valid response information is received from the target address - port pair, obtain the hidden domain name risk information of the object to be queried according to the un - resolved domain name and the target address - port pair; the hidden domain name risk information is used for domain name security repair of the object to be queried.
8. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Cited By
Intranet information leakage detection method, apparatus and device, and readable storage medium
CN120979724A