官术网_书友最值得收藏!

DNSRecon

DNSRecon is my go-to tool for DNS recon and enumeration. In this example, we will request a zone transfer from domain.foo. The DNS server running at domain.foo will return all of the records that it is aware of for domain.foo and any subdomains associated with it. This gives us the name of servers with their respective hostnames and IP addresses for the domain. It returned all DNS records, which were TXT records (4), PTR records (1), MX records for mail servers (10), IPv6 A records (2), and IPv4 A records (12). The records provide some really juicy information about the network. One record shows the IP address of their DC office, another shows the IP address of their firewall appliance, another shows that they have a VPN and its IP address, and another record shows the IP address of the mail server login portal, as shown in the following screenshot:

 dnsrecon -d zonetranfer.zone -a
-d: domain
-a: perform zone transfer

主站蜘蛛池模板: 凤台县| 黄梅县| 晋江市| 六安市| 清苑县| 龙里县| 唐海县| 舟曲县| 康保县| 扎鲁特旗| 鄂伦春自治旗| 理塘县| 炎陵县| 灌云县| 民丰县| 丹东市| 九江市| 南投县| 无极县| 平山县| 集安市| 松原市| 绿春县| 黑龙江省| 北票市| 盐亭县| 陆良县| 宜城市| 莆田市| 犍为县| 黄冈市| 莱州市| 遂溪县| 固镇县| 喀喇沁旗| 渝中区| 桂东县| 西吉县| 卫辉市| 香河县| 延庆县|