image.png

DNS servers need to be able to transfer zone information. However, this type of access should be password-protected at the very least.

Identify the IP Address of your ctf.local instance.

ping ctf.local

image.png

In my case, and yours will be different, the IP Address of ctf.local is 192.168.228.22.

dig axfr recon.icsi @192.168.228.22

image.png