πŸ˜†Port 53 (DNS)

Domain name system (DNS)

whois

whois <domain>
whois <ip>

Dig

dig axfr @dns-server domain.name
dig -x 10.10.10.10 @10.10.10.10

nslookup

nslookup <domain>

nslookup
set type=mx
set type=ns
dnsenum <DOMAIN>

Zone transfer

dnsrecon

the harvester

scrapea mails y mucha data

Recon-ng

webreconnaissance framework written in python

nmap

  • dns hostname lookup

  • Host Lookup host -t ns megacorpone.com `

  • Reverse Lookup Brute Force - find domains in the same range for ip in $(seq 155 190);do host 50.7.67.$ip;done |grep -v "not found"

  • Perform DNS IP Lookup

  • Reverse lookup

  • Perform MX Record Lookup

  • Perform Zone Transfer with DIG

  • Windows DNS zone transfer

  • Linux DNS zone transfer

  • Dnsrecon DNS Brute Force subdomain

  • Dnsrecon DNS List of megacorp

  • DNSEnum

DNS brute force

Last updated