14 DNS Enumeration
Dns数据库 属于主从类型的场景,其内容对于普通用户不可见,它提供了用户的ip和主机信息
dns 区域转移
host -t ns <域名或者ip>
#ns name server
host -t mx <域名或者ip>
mx maill server x可能是Exchange 也是邮件服务器的意思
host <域名或者ip>
#如果想要执行dns区域转移只需要以下语句
host -l <上面语句收集到的域名>
DNS区域传送原理及错误配置所引发问题 - FreeBuf网络安全行业门户
dnsrecon dns侦察工具
dnsrecon -d <目标域> -t axfr
-d +目标 -t axfr 表示做区域转移
#dnsrecon -d Target domain
# -t TYPE, --type TYPE Type of enumeration to perform.
## std: SOA, NS, A, AAAA, MX and SRV.
# rvl: Reverse lookup of a given CIDR or IP range.
# brt: Brute force domains and hosts using a given dictionary.
# srv: SRV records.
# axfr: Test all NS servers for a zone transfer.
# bing: Perform Bing search for subdomains and hosts.
# yand: Perform Yandex search for subdomains and hosts.
# crt: Perform crt.sh search for subdomains and hosts.
#snoop: Perform cache snooping against all NS servers for a given domain, testing
#all with file containing the domains, file given with -D option.
dnsnenum 域名
dnsenum +域名
这个速度很快的得到的信息很简洁