DNS Enumeration
NMAP DNS Hostnames LookupÂ
nmap -F --dns-server <dns server ip> <target ip range>
• Find Name Servers
host -t ns megacorpone.com
Find email servers
host -t mx guif.re
Perform DNS IP Lookup
dig a domain-name-here.com @nameserver
Perform MX Record Lookup
dig mx domain-name-here.com @nameserver
Dnsrecon DNS List of megacorp
dnsrecon -d megacorpone.com -t axfr
DNSEnum
dnsenum zonetransfer.me
Find Hosts.
dig guif.re a; @8.8.8.8 # types: a, mx, ns, soa, srv, txt, axfr
dig -x guif.re # reverse lookup
Web Services
./whatweb guif.reThere is a nice collection of OSINT tools
Map their infrastructure: middleware, programming languages, backends, services. This can help --> wapapawapa
Brute forcing For Data
Last updated