官术网_书友最值得收藏!

DNSRecon

DNSRecon is my go-to tool for DNS recon and enumeration. In this example, we will request a zone transfer from domain.foo. The DNS server running at domain.foo will return all of the records that it is aware of for domain.foo and any subdomains associated with it. This gives us the name of servers with their respective hostnames and IP addresses for the domain. It returned all DNS records, which were TXT records (4), PTR records (1), MX records for mail servers (10), IPv6 A records (2), and IPv4 A records (12). The records provide some really juicy information about the network. One record shows the IP address of their DC office, another shows the IP address of their firewall appliance, another shows that they have a VPN and its IP address, and another record shows the IP address of the mail server login portal, as shown in the following screenshot:

 dnsrecon -d zonetranfer.zone -a
-d: domain
-a: perform zone transfer

主站蜘蛛池模板: 马公市| 深泽县| 神农架林区| 项城市| 松滋市| 金山区| 元朗区| 东源县| 景德镇市| 凤山县| 夏邑县| 乌什县| 沂南县| 乌鲁木齐县| SHOW| 金川县| 海兴县| 永安市| 桃源县| 万源市| 宜阳县| 安岳县| 竹北市| 邢台县| 云和县| 南宁市| 渭源县| 彩票| 普兰店市| 绥芬河市| 偃师市| 上蔡县| 高淳县| 教育| 漳浦县| 云霄县| 太仆寺旗| 澎湖县| 佛山市| 宝兴县| 淮南市|