DNS Enumeration

Find DNS server

nmap -p 53 -sV 192.168.1.0/24 --open

Reverse lookup

Using DNSRecon

dnsrecon -r 192.168.1.0/24 -n <NS IP>

Using host

for ip in $(seq  1 254); do host 192.168.1.$ip <NS IP>; done | grep -v "not found"

Zone transfers

Using host

host -l <domain name> <ns server>

Using dig

dig axfr <domain or subdomain> @<NS IP>

Try zone transfer on each DNS servers

Last updated