Thursday, 23 June 2011

dns enumeration

Quick note on DNS enumeration since I might not remember this tool in the morning..

Fierce will use the hosts.txt file that lives in the directory below to lookup any possible DNS A records
root@bt:/pentest/enumeration/dns/fierce# ./ -dns -threads 5 -wide
DNS Servers for

Trying zone transfer first...
Request timed out or transfer not allowed.
Request timed out or transfer not allowed.

Unsuccessful in zone transfer (it was worth a shot)
Okay, trying the good old fashioned way... brute force

Checking for wildcard DNS...
Nope. Good.
Now performing 1895 test(s)...

result snip

Subnets found (may want to probe here using nmap or unicornscan): : 1 hostnames found. : 8 hostnames found. : 9 hostnames found. : 19 hostnames found. : 2 hostnames found. : 3 hostnames found.

Done with Fierce scan:
Found 42 entries.

Have a nice day.

Indeed we will :)

No comments:

Post a Comment