官术网_书友最值得收藏!

DNSRecon

DNSRecon is my go-to tool for DNS recon and enumeration. In this example, we will request a zone transfer from domain.foo. The DNS server running at domain.foo will return all of the records that it is aware of for domain.foo and any subdomains associated with it. This gives us the name of servers with their respective hostnames and IP addresses for the domain. It returned all DNS records, which were TXT records (4), PTR records (1), MX records for mail servers (10), IPv6 A records (2), and IPv4 A records (12). The records provide some really juicy information about the network. One record shows the IP address of their DC office, another shows the IP address of their firewall appliance, another shows that they have a VPN and its IP address, and another record shows the IP address of the mail server login portal, as shown in the following screenshot:

 dnsrecon -d zonetranfer.zone -a
-d: domain
-a: perform zone transfer

主站蜘蛛池模板: 台前县| 庆阳市| 宝坻区| 濮阳县| 织金县| 淮阳县| 临城县| 永仁县| 调兵山市| 云龙县| 黔江区| 闻喜县| 闽侯县| 德安县| 自贡市| 理塘县| 彩票| 博野县| 霞浦县| 清苑县| 肇州县| 凌海市| 襄汾县| 安康市| 河西区| 雷波县| 高淳县| 甘泉县| 禹城市| 米易县| 育儿| 上虞市| 江都市| 岗巴县| 罗城| 蛟河市| 随州市| 旌德县| 汾西县| 泾阳县| 芒康县|