Nsec3map

a tool to enumerate the resource records of a DNS zone using its DNSSEC NSEC or NSEC3 chain

Cybersecurity & Ethical HackingPythonGPL-3.0

Abstract

Nsec3map is an open-source Cybersecurity & Ethical Hacking project. A tool to enumerate the resource records of a DNS zone using its DNSSEC NSEC or NSEC3 chain. The -v switch is only used for more verbosity and not generally needed. With no further arguments, nsec3map detects automatically whether the zone uses NSEC or NSEC3 and uses the corresponding enumeration method. It is built using Python. The complete source code is publicly available on GitHub under the GNU General Public License v3.0, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.

1. Introduction

The -v switch is only used for more verbosity and not generally needed. With no further arguments, nsec3map detects automatically whether the zone uses NSEC or NSEC3 and uses the corresponding enumeration method. It also looks up the zone's nameservers by itself.

This will cause nsec3map to send a maximum of 16 queries in parallel while at the same time keeping the query rate at or below roughly 100 queries per second.

This will first read the NSEC3 records from example.com.partial and then continue the enumeration, saving the NSEC3 chain to example.com.zone. The --ignore-overlapping option should be used for large zones, or if it is otherwise likely that changes are made to the zone during the enumeration. If specified, nsec3map will not abort the enumeration when it receives an NSEC3 record which overlaps with another record that was received earlier. Note however that you will not get a completely consistent view of the NSEC3 chain if you use this option.

2. Objective

a tool to enumerate the resource records of a DNS zone using its DNSSEC NSEC or NSEC3 chain

This project demonstrates how Python can be applied to a real-world Cybersecurity & Ethical Hacking problem.

4. Technology Stack

Python

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • Python 3.8 or later
  • pip / virtualenv for dependencies
  • VS Code, PyCharm or Jupyter Notebook
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/anonion0/nsec3map.git
cd nsec3map

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add logging and alert notifications (email / Telegram)
  • Write a threat model document for the tool
  • Package it with Docker for safe lab testing

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Which threat or attack does this project defend against?
  2. What detection or protection technique is used and what are its limits?
  3. How are false positives and false negatives handled?
  4. Which cryptographic algorithms or security standards are involved?
  5. What legal and ethical rules apply when testing a tool like this?

9. Source Code & License

This project is developed by anonion0 and published on GitHub under the GNU General Public License v3.0. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Cybersecurity & Ethical Hacking Internship