HTB STARTING POINT · Tier 1

Facts

DNS zone transfer (AXFR) exposes internal hostnames including a development subdomain. The dev site runs an unauthenticated API that returns SSH credentials in plaintext.…

April 28, 2026 · 3 min · crAIzy
DNS Zone TransferAPI Exposure