← All cheat sheets

LBD

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

lbd (Load Balancing Detector) detects if a given domain is using
DNS and/or HTTP load balancing. It checks for multiple IPs in DNS
responses and differences in HTTP headers across requests.

BASIC USAGE#

lbd <domain>                     # Detect load balancing

EXAMPLES#

# Check if domain uses load balancing
lbd example.com

# Check a specific subdomain
lbd www.example.com

# Check an application server
lbd app.example.com

DETECTION METHODS#

# DNS-based detection:
# - Performs multiple DNS lookups
# - Compares returned IP addresses
# - Different IPs indicate DNS round-robin load balancing

# HTTP-based detection:
# - Sends multiple HTTP requests
# - Compares server headers (Server, Date, ETag, etc.)
# - Differences indicate HTTP load balancing
# - Checks for cookies set by load balancers

INTERPRETING OUTPUT#

# DNS Load Balancing:
# "DNS-Loadbalancing: FOUND" = multiple IPs detected
# "DNS-Loadbalancing: NOT FOUND" = single IP

# HTTP Load Balancing:
# "HTTP-Loadbalancing: FOUND" = differences in HTTP responses
# "HTTP-Loadbalancing: NOT FOUND" = consistent responses

# Indicators checked:
# - Server header differences
# - Date header variations (beyond normal drift)
# - Different ETag values
# - Varying content lengths
# - Load balancer cookies (BIGipServer, JSESSIONID, etc.)

COMMON LOAD BALANCER INDICATORS#

# Cookie names that reveal load balancers:
# BIGipServer*     = F5 BIG-IP
# JSESSIONID       = Java app servers (sticky sessions)
# AWSALB           = AWS Application Load Balancer
# SERVERID         = HAProxy
# X-Forwarded-For  = Generic reverse proxy/LB
# __cfduid         = Cloudflare

# Header indicators:
# X-Served-By      = Varnish/CDN
# X-Cache          = Caching proxy
# Via              = Proxy/CDN
# X-Backend-Server = Reverse proxy

MANUAL VERIFICATION#

# DNS check
dig +short example.com
dig +short example.com
# Compare multiple lookups for different IPs

# HTTP header comparison
curl -sI https://example.com | grep -i server
curl -sI https://example.com | grep -i server
# Compare responses for differences

NOTES#

- Simple bash script using dig and HTTP requests
- No special dependencies beyond dig and netcat/curl
- Quick first-step for infrastructure reconnaissance
- False positives possible with CDNs
- Helps determine target infrastructure complexity
- Useful for scoping penetration tests