LBD
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
lbd (Load Balancing Detector) detects if a given domain is using DNS and/or HTTP load balancing. It checks for multiple IPs in DNS responses and differences in HTTP headers across requests.
BASIC USAGE#
lbd <domain> # Detect load balancing
EXAMPLES#
# Check if domain uses load balancing lbd example.com # Check a specific subdomain lbd www.example.com # Check an application server lbd app.example.com
DETECTION METHODS#
# DNS-based detection: # - Performs multiple DNS lookups # - Compares returned IP addresses # - Different IPs indicate DNS round-robin load balancing # HTTP-based detection: # - Sends multiple HTTP requests # - Compares server headers (Server, Date, ETag, etc.) # - Differences indicate HTTP load balancing # - Checks for cookies set by load balancers
INTERPRETING OUTPUT#
# DNS Load Balancing: # "DNS-Loadbalancing: FOUND" = multiple IPs detected # "DNS-Loadbalancing: NOT FOUND" = single IP # HTTP Load Balancing: # "HTTP-Loadbalancing: FOUND" = differences in HTTP responses # "HTTP-Loadbalancing: NOT FOUND" = consistent responses # Indicators checked: # - Server header differences # - Date header variations (beyond normal drift) # - Different ETag values # - Varying content lengths # - Load balancer cookies (BIGipServer, JSESSIONID, etc.)
COMMON LOAD BALANCER INDICATORS#
# Cookie names that reveal load balancers: # BIGipServer* = F5 BIG-IP # JSESSIONID = Java app servers (sticky sessions) # AWSALB = AWS Application Load Balancer # SERVERID = HAProxy # X-Forwarded-For = Generic reverse proxy/LB # __cfduid = Cloudflare # Header indicators: # X-Served-By = Varnish/CDN # X-Cache = Caching proxy # Via = Proxy/CDN # X-Backend-Server = Reverse proxy
MANUAL VERIFICATION#
# DNS check dig +short example.com dig +short example.com # Compare multiple lookups for different IPs # HTTP header comparison curl -sI https://example.com | grep -i server curl -sI https://example.com | grep -i server # Compare responses for differences
NOTES#
- Simple bash script using dig and HTTP requests - No special dependencies beyond dig and netcat/curl - Quick first-step for infrastructure reconnaissance - False positives possible with CDNs - Helps determine target infrastructure complexity - Useful for scoping penetration tests