TryHackMe (THM) Dig Dug Walkthrough
🔗Room Link : https://tryhackme.com/room/digdug
TryHackMe (THM) Dig Dug Walkthrough
🔗Room Link : https://tryhackme.com/room/digdug
This room focuses on DNS enumeration and how misconfigured DNS servers can expose sensitive information.

Deploy the room and note the MACHINE_IP.
Oooh, turns out, this MACHINE_IP machine is also a server! If we could dig into it, I am sure we could find some interesting records! But… it seems weird, this only responds to a special type of request for a givemetheflag.com domain?
Use nslookup to query the target DNS server:
nslookup givemetheflag.com MACHINE_IP

The flag is directly revealed in the TXT record.
Alternate commands :
dig -t txt @MACHINE_IP givemetheflag.com
Summary of Concepts
DNS Enumeration is the process of querying DNS servers to extract hidden information such as records and metadata.
Core Points:
- DNS servers can store hidden data in TXT records
- Tools like
digandnslookupare used for querying - Misconfigured DNS can expose sensitive information
- Common in reconnaissance and CTF challenges
- DNS can be abused for data exfiltration
메타데이터
- post_id
- 3de5fc0d8768
- slug
- tryhackme-thm-dig-dug-walkthrough-3de5fc0d8768
- url
- https://medium.com/@diwanimh007/tryhackme-thm-dig-dug-walkthrough-3de5fc0d8768
- canonical_url
- https://medium.com/@diwanimh007/tryhackme-thm-dig-dug-walkthrough-3de5fc0d8768
- author_url
- https://medium.com/@diwanimh007
- status
- ok
- fetched_at
- 2026-07-14 07:07:08