DNS Enumeration

DNS Enumeration

  • host <website>

  • host -t mx <domain>

  • ****************************************************Forward Lookup bruteforce for ip in $(cat list.txt); do host $ip.megacorpone.comarrow-up-right; done where list.txt has all subdomain

  • Forward Lookup bruteforce for ip in $(seq 50 100); do host 38.100.193.$ip; done | grep -v "not found”

Dnsrecon tool (DNS Zone transfer)arrow-up-right

DNS Zone transfer (using dig)arrow-up-right

Dnsrecon tool (DNS Zone transfer)

DNS Zone transfer (using dig)

  • dig axfr <domain> @<server-ip or machine ip>

    • dig axfr friendzone.red @10.10.10.123

Last updated