Domain Name Service

Footprinting the Service

DIG - NS Query

DIG - Version Query

DIG - ANY Query

DIG - AXFR Zone Transfer

DIG - AXFR Zone Transfer - Internal

Using subdomain internal from previous zone transfer on inlanefreight.htb. Also attemp to do zonetransfers and all subdomains.

Subdomain Brute Forcing

dnsenum

dnsrecon

Passive Subdomain Enumeration

virustotal

certificates

crt.sh

Another source of information we can use to extract subdomains is SSL/TLS certificates. The main reason is Certificate Transparency (CT).

A project that requires every SSL/TLS certificate issued by a Certificate Authority (CA) to be published in a publicly accessible log

perform a curl request to the target website asking for a JSON output as this is more manageable

Passive Infrastructure Identification

Wayback Machine

you can find old versions that may have interesting comments in the source code or files that should not be there

Waybackurls

Dangerous Settings

allow-query

Defines which hosts are allowed to send requests to the DNS server.

allow-recursion

Defines which hosts are allowed to send recursive requests to the DNS server.

allow-transfer

Defines which hosts are allowed to receive zone transfers from the DNS server.

zone-statistics

Collects statistical data of zones.

Last updated