官术网_书友最值得收藏!

How to do it...

  1. To view the help, we type the following:
dnsrecon -h

The following screenshot shows the output of the preceding command:

  1. To do a simple recon of name servers, A records, SOA records, MX records, and so on, we can run the following command:
dnsrecon -d packtpub.com -n 8.8.8.8

The following screenshot shows the output of the preceding command:

  1. Now let's take an example of a domain that has NSEC records. To do a zone walk, we can simply run the following command:
dnsrecon -z -d icann.org -n 8.8.8.8

The following screenshot shows the output of the preceding command:

  1. We can do this manually by using the dig command along with dig +short NSEC domainname.com.
  2. The previous dig command will throw us one subdomain, and then we can rerun the same command with the subdomain we got in previous step to find the next subdomain: dig +short NSEC a.domain.com.
主站蜘蛛池模板: 重庆市| 永定县| 灵宝市| 绥芬河市| 兴安县| 江华| 上犹县| 稷山县| 灵寿县| 宁波市| 轮台县| 金湖县| 改则县| 平和县| 洱源县| 兴和县| 广饶县| 石嘴山市| 长治市| 方正县| 南宫市| 丽水市| 高尔夫| 广元市| 凉城县| 盐池县| 黑山县| 镇远县| 新乡市| 噶尔县| 兴化市| 嘉祥县| 余庆县| 文化| 罗甸县| 正安县| 石景山区| 韶关市| 罗江县| 乌兰浩特市| 拜城县|