Skip to content

DNS Enumeration

lethanhtung01011980 edited this page Dec 27, 2019 · 6 revisions

Basics DNS

  • host -t ns abc.com
  • host -t mx abc.com
  • host www.abc.com
  • Brute force lookup: for ip in $(cat list.txt);do host $ip.abc.com;done
  • Reverse lookup: for ip in $(seq 155 190);do host x.x.x.$ip;done |grep -v "not found"

DNS Zone transfer

Copying of the zone file from a master DNS server to a hacker server.

  • host -l <domain name> <dns server address>

DNSRecon

  • dnsrecon -d abc.com -t axfr

Sidebar

0. COMMON exploits

1. Scan Info

1.2 Passive Gathering

1.3 Active Gathering

2. Pre-attack

2.2 File transfer

3. Get Reverse Shell

4. Exploits

4.2 Windows Exploits

4.3 Linux Exploits

4.4 Password crack

4.5 Buffer Overflow

4.6 Web attacks

6. Escalate Privilege

6.1 Escalate in Windows

6.2 Escalate in Linux

7. Access and further attacks

8. Port redirection and Tunnelling

9. Metasploit

10. Kali

11. Thirdparty scripts

Clone this wiki locally