53 - DNS
The Domain Name System is a hierarchical and decentralized naming system for computers, services, or other resources connected to the Internet or a private network.
nslookup
SERVER {DNS Server}
{IP we want to check}
Records lookups
dig a domainname.com @nameserver
dig mx domainname.com @nameserver Find name server (NS)
root@Kali:~# dig ns zonetransfer.me
[snip]
;; ANSWER SECTION:
zonetransfer.me. 7186 IN NS nsztm2.digi.ninja.
zonetransfer.me. 7186 IN NS nsztm1.digi.ninja. Dnsrecon
Dnsrecon.py -d {domain}
Link: https://github.com/darkoperator/dnsrecon
Reverse lookup:
./dnsrecon.py -r <startIP-endIP>
Dig
view all dns records
dig zonetransfer.me -t ANY
Zone transfer
Using dig first find NS Server::
Perform zone transfer:
Using nmap
nmap --script dns-zone-transfer.nse --script-args dns-zone-transfer.domain=zonetrasnfer.me -p53
Using dnsrecon
Last updated
Was this helpful?