被动信息收集1
>被动信息收集
- 公开渠道可获得的信息
- 与目标系统不进行直接交互
- 尽量避免留下一切痕迹
- 信息收集内容:IP地址、域名信息、邮件地址、文档图片数据、公司地址、公司组织架构、联系电话/传真号码、人员姓名/职务、目标系统使用的技术架构、公开的商业信息等
- 信息用途:用信息描述目标、社会工程学攻击、发现、物理缺口
>域名系统DNS
- DNS(Domain Name System)域名系统
- 将域名和IP地址相互映射(正向解析:域名—>IP地址)
- 端口:TCP/UDP 53
- 目前,每级域名长度<=63,域名总长度<=253
- 记录类型:A(主机记录)、CNAME(别名记录)、MX(邮件交换记录)、NS(域名服务器记录)、PTR(邮件交换中的反向地址解析)、AAA(IPv6主机记录)、SRV(服务位置记录)、NAPTR(正则表达方式映射域名)等
- FQND(Fully Qualified Domain Name)完全合格域名/全称域名,指主机名加上全路径(全路径列出了序列中的所有域成员)
如:百度的域名为baidu.con,FQND为www.baidu.com
- DNS服务器解析流程
>DNS信息收集——nslookup
- nslookup,查询DNS记录、监测DNS服务器是否能正确实现域名解析
- 交互式界面
root@xuer:~# nslookup
> server
Default server: 192.168.10.2
Address: 192.168.10.2#53
> sina.com
Server: 192.168.10.2
Address: 192.168.10.2#53
Non-authoritative answer:
Name: sina.com
Address: 66.102.251.33
> set type=mx
> sina.com
Server: 192.168.10.2
Address: 192.168.10.2#53
Non-authoritative answer:
sina.com mail exchanger = 10 freemx2.sinamail.sina.com.cn.
sina.com mail exchanger = 10 freemx3.sinamail.sina.com.cn. #5,10表示优先级
sina.com mail exchanger = 5 freemx1.sinamail.sina.com.cn. #优先级5高于10
Authoritative answers can be found from:
- 直接解析
nslookup -type=ns sina.com
nslookup -q=ns sina.com # -type参数与-p参数,都可指定记录类型
root@xuer:~# nslookup -type=ns sina.com
Server: 192.168.10.2
Address: 192.168.10.2#53
Non-authoritative answer:
sina.com nameserver = ns1.sina.com.cn.
sina.com nameserver = ns3.sina.com.
sina.com nameserver = ns3.sina.com.cn.
sina.com nameserver = ns2.sina.com.cn.
sina.com nameserver = ns2.sina.com.
sina.com nameserver = ns4.sina.com.
sina.com nameserver = ns4.sina.com.cn.
sina.com nameserver = ns1.sina.com.
Authoritative answers can be found from:
root@xuer:~# nslookup -q=ns sina.com
Server: 192.168.10.2
Address: 192.168.10.2#53
Non-authoritative answer:
sina.com nameserver = ns2.sina.com.cn.
sina.com nameserver = ns2.sina.com.
sina.com nameserver = ns4.sina.com.
sina.com nameserver = ns1.sina.com.cn.
sina.com nameserver = ns3.sina.com.
sina.com nameserver = ns1.sina.com.
sina.com nameserver = ns3.sina.com.cn.
sina.com nameserver = ns4.sina.com.cn.
Authoritative answers can be found from:
>DNS信息收集——dig
- 解析特定域名记录的域名
dig @8.8.8.8 mx sina.com
root@xuer:~# dig @8.8.8.8 mx sina.com
; <<>> DiG 9.11.3-1-Debian <<>> @8.8.8.8 sina.com mx
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 35085
;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;sina.com. IN MX
;; ANSWER SECTION:
sina.com. 59 IN MX 10 freemx2.sinamail.sina.com.cn.
sina.com. 59 IN MX 10 freemx3.sinamail.sina.com.cn.
sina.com. 59 IN MX 5 freemx1.sinamail.sina.com.cn.
;; Query time: 176 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Sun Apr 07 16:19:47 CST 2019
;; MSG SIZE rcvd: 129
- 解析某DNS全部域名
dig @8.8.8.8 sina.com any #dig @DNS服务器 域名
root@xuer:~# dig @8.8.8.8 mx sina.com
; <<>> DiG 9.10.3-P4-Debian <<>> @8.8.8.8 mx sina.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 61484
;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;sina.com. IN MX
;; ANSWER SECTION:
sina.com. 60 IN MX 10 freemx2.sinamail.sina.com.cn.
sina.com. 60 IN MX 5 freemx1.sinamail.sina.com.cn.
sina.com. 60 IN MX 10 freemx3.sinamail.sina.com.cn.
;; Query time: 63 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Tue Apr 23 16:39:59 CST 2019
;; MSG SIZE rcvd: 129
- 筛选过滤解析(筛选出answer项)
dig +noall +answer @8.8.8.8 sina.com any
root@xuer:~# dig +noall +answer @8.8.8.8 sina.com any
sina.com. 59 IN A 66.102.251.33
sina.com. 59 IN TXT "v=spf1 include:spf.sinamail.sina.com.cn -all"
sina.com. 299 IN SOA ns1.sina.com.cn. zhihao.staff.sina.com.cn. 2005042601 900 300 604800 300
sina.com. 21599 IN NS ns2.sina.com.
sina.com. 21599 IN NS ns2.sina.com.cn.
sina.com. 21599 IN NS ns3.sina.com.cn.
sina.com. 21599 IN NS ns4.sina.com.cn.
sina.com. 21599 IN NS ns1.sina.com.cn.
sina.com. 21599 IN NS ns1.sina.com.
sina.com. 21599 IN NS ns4.sina.com.
sina.com. 21599 IN NS ns3.sina.com.
sina.com. 59 IN MX 5 freemx1.sinamail.sina.com.cn.
sina.com. 59 IN MX 10 freemx2.sinamail.sina.com.cn.
sina.com. 59 IN MX 10 freemx3.sinamail.sina.com.cn.
- 反向查询