dnsenum信息收集

dnsenum是一个用于获取域名相关信息的工具,它也可以用于在DNS服务器上暴力破解子域。它是一个多线程perl脚本,可以收集A记录并查询Google或wordlist来发现子域。它还可以获取主机地址、namservers、MX记录,执行axfr查询并获取BIND版本,通过google抓取获取额外的名称和子域,对具有NS记录的子域执行递归,计算C类域网络范围并对它们执行whois查询,对网络范围执行反向查找,并将结果写入domain_ips.txt文件。
其下载地址:
https://gitlab.com/ibnunowshad/dnsenum.git
https://github.com/fwaeytens/dnsenum

1.1dnsenum常见命令

以下是dnsenum的命令行用法和选项说明:
Usage: dnsenum [Options]
[选项]:
注意:如果未提供-f选项,则默认使用/usr/share/dnsenum/dns.txt文件或与dnsenum相同目录中的dns.txt文件。
常规选项:
–dnsserver 使用指定的DNS服务器进行A、NS和MX查询。
–enum 快捷选项,相当于–threads 5 -s 15 -w。
-h, --help 显示帮助信息。
–noreverse 跳过反向查询操作。
–nocolor 禁用ANSIColor输出。
–private 在domain_ips.txt文件末尾显示和保存私有IP。
–subfile 将所有有效的子域名写入此文件。
-t, --timeout TCP和UDP超时值,以秒为单位(默认为10秒)。
–threads 执行不同查询的线程数。
-v, --verbose 显示全部进度和错误消息。
GOOGLE SCRAPING选项:
-p, --pages 处理google搜索页面的数量(默认为5页),必须指定-s选项。
-s, --scrap 从Google中最多抓取的子域名数(默认15个)。
暴力破解选项:
-f, --file 从此文件中读取子域名以执行暴力破解(优先于默认的dns.txt)。
-u, --update <a|g|r|z> 使用有效的子域名更新-f选项指定的文件。
a (all) 使用所有结果进行更新。
g 仅使用Google抓取结果进行更新。
r 仅使用反向查询结果进行更新。
z 仅使用区域传送结果进行更新。
-r, --recursion 对子域名进行递归,对所有具有NS记录的发现的子域名执行暴力破解。
WHOIS NETRANGE选项:
-d, --delay 在whois查询之间等待的最大秒数,该值是随机定义的,默认为3秒。
-w, --whois 对C类网络范围执行whois查询。
警告:这可能会生成非常大的网络范围,并且执行反向查询需要很长时间。
反向查询选项:
-e, --exclude 从反向查询结果中排除与正则表达式匹配的PTR记录,对无效的主机名很有用。
输出选项:
-o --output 以XML格式输出。可以在MagicTree(www.gremwell.com)中导入。

1.2dnsenum使用样例

1.枚举一个域名的子域名、主机、MX记录和NS记录
dnsenum sina.com

dnsenum sina.com
dnsenum VERSION:1.2.6

-----   sina.com   -----


Host's addresses:
__________________

sina.com.                                5        IN    A        64.71.151.11


Name Servers:
______________

ns3.sina.com.cn.                         5        IN    A        123.125.29.99
ns4.sina.com.                            5        IN    A        123.125.29.99
ns2.sina.com.cn.                         5        IN    A        180.149.138.199
ns1.sina.com.cn.                         5        IN    A        221.179.193.14
ns4.sina.com.cn.                         5        IN    A        183.60.92.12
ns3.sina.com.                            5        IN    A        180.149.138.199
ns2.sina.com.                            5        IN    A        114.134.80.165
ns1.sina.com.                            5        IN    A        114.134.80.137


Mail (MX) Servers:
___________________

freemx3.sinamail.sina.com.cn.            5        IN    A        49.7.36.189
freemx1.sinamail.sina.com.cn.            5        IN    A        49.7.36.189
freemx2.sinamail.sina.com.cn.            5        IN    A        123.126.45.192


Trying Zone Transfers and getting Bind Versions:
_________________________________________________


Trying Zone Transfer for sina.com on ns3.sina.com.cn ...
AXFR record query failed: NOTAUTH

Trying Zone Transfer for sina.com on ns4.sina.com ...
AXFR record query failed: NOTAUTH

Trying Zone Transfer for sina.com on ns2.sina.com.cn ...
AXFR record query failed: NOTAUTH

Trying Zone Transfer for sina.com on ns1.sina.com.cn ...
AXFR record query failed: NOTAUTH

Trying Zone Transfer for sina.com on ns4.sina.com.cn ...
AXFR record query failed: NOTAUTH

Trying Zone Transfer for sina.com on ns3.sina.com ...
AXFR record query failed: NOTAUTH

Trying Zone Transfer for sina.com on ns2.sina.com ...
AXFR record query failed: NOTAUTH

Trying Zone Transfer for sina.com on ns1.sina.com ...
AXFR record query failed: NOTAUTH


Brute forcing with /usr/share/dnsenum/dns.txt:
_______________________________________________

ads.sina.com.                            5        IN    CNAME    ww1.sinaimg.cn.                                                                                                                                   w.alikunlun.com.
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        60.28.196.210
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        124.163.194.239
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        221.194.147.223
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        60.28.226.41
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        121.17.123.118
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        221.194.147.219
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        211.93.250.27
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        125.39.43.89
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        125.39.43.93
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        211.93.250.30
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        61.182.130.242
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        60.28.226.43
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        121.17.123.115
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        60.28.196.217
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        61.182.130.248
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        124.163.194.245
blog.sina.com.                           5        IN    CNAME    blog.sina.com.c                                                                                                                                   n.
blog.sina.com.cn.                        5        IN    CNAME    blogx.sina.com.                                                                                                                                   cn.
blogx.sina.com.cn.                       5        IN    A        202.108.0.52
client.sina.com.                         5        IN    A        10.10.10.10
election.sina.com.                       5        IN    CNAME    ww10.sina.com.
ww10.sina.com.                           5        IN    A        71.5.7.191
elections.sina.com.                      5        IN    CNAME    ww10.sina.com.
ww10.sina.com.                           5        IN    A        71.5.7.191
europe.sina.com.                         5        IN    CNAME    spit.sina.com.
spit.sina.com.                           5        IN    A        71.5.7.171
finance.sina.com.                        5        IN    A        10.10.10.10
forum.sina.com.                          5        IN    CNAME    us.sina.com.
us.sina.com.                             5        IN    CNAME    ussina.gslb.sinaedge.com.
ussina.gslb.sinaedge.com.                5        IN    CNAME    ww1.sinaimg.cn.w.alikunlun.com.
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        221.194.147.219
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        60.28.196.211
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        60.28.226.26
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        60.28.226.41
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        125.39.43.92
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        61.182.130.206
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        124.163.194.244
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        121.17.123.113
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        211.93.250.34
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        125.39.43.91
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        61.182.130.213
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        211.93.250.27
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        124.163.194.245
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        60.28.196.210
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        221.194.147.218
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        121.17.123.114
forums.sina.com.                         5        IN    CNAME    us.sina.com.
us.sina.com.                             5        IN    CNAME    ussina.gslb.sinaedge.com.
ussina.gslb.sinaedge.com.                5        IN    CNAME    ww1.sinaimg.cn.w.alikunlun.com.
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        125.39.43.88
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        60.28.196.216
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        61.182.130.241
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        211.93.250.28
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        60.28.196.212
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        60.28.226.48
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        124.163.194.245
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        121.17.123.117
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        211.93.250.30
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        221.194.147.223
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        125.39.43.91
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        121.17.123.113
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        221.194.147.218
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        60.28.226.44
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        124.163.194.241
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        61.182.130.242
fr.sina.com.                             5        IN    A        10.182.10.122
ftp.sina.com.                            5        IN    CNAME    blossom.sina.com.
blossom.sina.com.                        5        IN    A         71.5.7.14
g.sina.com.                              5        IN    A        202.106.169.230
jobs.sina.com.                           5        IN    CNAME    spit.sina.com.
spit.sina.com.                           5        IN    A        71.5.7.171
lists.sina.com.                          5        IN    A        66.102.251.33
log.sina.com.                            5        IN    CNAME    log1.sina.com.
mail.sina.com.                           5        IN    CNAME    mail.sina.com.cn.
mail.sina.com.cn.                        5        IN    CNAME    alb00000053.dpool.sina.com.cn.
alb00000053.dpool.sina.com.cn.           5        IN    A        202.108.0.139
marketing.sina.com.                      5        IN    A        71.5.7.205
members.sina.com.                        5        IN    A        66.102.251.33
ns.sina.com.                             5        IN    CNAME    resolver3.sina.com.
resolver3.sina.com.                      5        IN    A        71.5.7.135
ns1.sina.com.                            5        IN    A        114.134.80.137
ns2.sina.com.                            5        IN    A        114.134.80.165
ns3.sina.com.                            5        IN    A        180.149.138.199
pan.sina.com.                            5        IN    CNAME    dudelove3.sina.com.
dudelove3.sina.com.                      5        IN    A        71.5.7.234
pop.sina.com.                            5        IN    CNAME    pop3.sina.com.cn.
pop3.sina.com.cn.                        5        IN    A        49.7.36.85
register.sina.com.                       5        IN    A        71.5.7.111
search.sina.com.                         5        IN    A         71.5.7.11
smtp.sina.com.                           5        IN    CNAME    smtp.sina.com.cn.
smtp.sina.com.cn.                        5        IN    A        123.126.45.161
sp.sina.com.                             5        IN    CNAME    spit.sina.com.
spit.sina.com.                           5        IN    A        71.5.7.171
stats.sina.com.                          5        IN    CNAME    darklighter.sina.com.
darklighter.sina.com.                    5        IN    A         71.5.7.51
survey.sina.com.                         5        IN    CNAME    ww1.sinaimg.cn.w.alikunlun.com.
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        121.17.123.115
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        211.93.250.29
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        221.194.147.219
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        221.194.147.217
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        60.28.196.214
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        124.163.194.244
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        60.28.196.211
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        60.28.226.53
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        211.93.250.30
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        124.163.194.239
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        125.39.43.88
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        61.182.130.250
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        61.182.130.249
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        121.17.123.116
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        60.28.226.48
ww1.sinaimg.cn.w.alikunlun.com.          5        IN    A        125.39.43.87
voip.sina.com.                           5        IN    CNAME    voip.sina.cn.
vpn.sina.com.                            5        IN    A        123.126.45.247
webaccess.sina.com.                      5        IN    A         71.5.7.97
win.sina.com.                            5        IN    A        202.108.33.18
ww.sina.com.                             5        IN    A        61.135.153.194
ww3.sina.com.                            5        IN    CNAME    spit.sina.com.
spit.sina.com.                           5        IN    A        71.5.7.171
www.sina.com.                            5        IN    CNAME    spool.grid.sinaedge.com.
spool.grid.sinaedge.com.                 5        IN    A        123.126.45.205


sina.com class C netranges:
____________________________

 61.135.153.0/24
 64.71.151.0/24
 66.102.251.0/24
 71.5.7.0/24
 114.134.80.0/24
 123.125.29.0/24
 123.126.45.0/24
 180.149.138.0/24
 202.106.169.0/24
 202.108.33.0/24


2.使用指定的DNS服务器进行枚举
dnsenum --dnsserver 8.8.8.8 example.com
3.禁用反向查询操作
dnsenum --noreverse example.com
4.从指定文件中读取子域名以执行暴力破解
dnsenum -f subdomains.txt example.com
5.使用所有结果更新指定文件
dnsenum -u a -f subdomains.txt example.com
6.对子域名进行递归,对所有具有NS记录的发现的子域名执行暴力破解
dnsenum -r example.com
7.执行whois查询,并进行反向查询
dnsenum -w example.com
8.输出结果到XML文件并禁用ANSIColor输出
dnsenum --nocolor -o output.xml example.com

  • 0
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

我是simeon

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值