当前位置:网站首页>Kali system -- host, dig, dnsenum, imtry for DNS collection and analysis
Kali system -- host, dig, dnsenum, imtry for DNS collection and analysis
2022-06-13 00:32:00 【P1n9】
host Tools
1>Host The instruction provides a simple DNS The function of parsing . Use the name normally to IP Parsing , When the instruction does not have any parameters and options , It will output a simple summary with command line parameters and options .
A name is a domain name that can be resolved , It can also be dotted decimal IPV4 Addresses or colon delimited IPV6 The address of , By default , You can also perform a reverse parsing function ,DNS The server has both a name and IP Address ,host Queries can replace them , Or it can be listed in /etc/resolv.conf In the document
2> The specific use :
-a Show detailed DNS Information ;
-c< type > Specify the query type , The default value is “IN“;
-C Query the complete SOA Record ;
-r When querying domain names , Do not use recursive queries ;
-t< type > Specify the domain name information type of the query ;
-v Show the details of instruction execution ;
-w If the domain name server does not give an answer , Always waiting , Until the DNS server answers ;
-W< Time > Specify the maximum time for domain name query , If the domain name server does not give a response within the specified time , Then exit the command ;
-4 Use IPv4;
-6 Use IPv6.
3> The specific methods :
The use of dns The server /etc/resolv.conf In file 
Test Baidu 
Use custom dns The server 
Show detailed records 
dig
1>dig( Domain information searcher ) A command is a command used to ask DNS Flexible tools for DNS . It performs DNS Search for , Displays the replies returned from the requested domain name server . Most of the DNS Administrator utilization dig As DNS Fault diagnosis of the problem , Because it's flexible 、 Easy to use 、 Clear output .
Although usually dig Use command line arguments , But it can also read search requests from files in batch mode . Unlike earlier versions ,dig Of BIND9 Implementation allows multiple queries to be issued from the command line . Unless told to request a specific domain name server ,dig Will try /etc/resolv.conf All servers listed in . When no command line parameters or options are specified ,dig Will be right “.”( root ) perform NS Inquire about .
2> Command options 
dns Details of different records :
https://www.cnblogs.com/momenglin/p/8556079.html
3>



dnsenum
1>dnsenum Is a very powerful domain name information collection tool , It is the participation of Backtack Designed by the programmer of the development project , Designer's name Fillp(barbsie) Waeythens , The developer is a master web Security personnel for penetration testing , Also on DNS I have rich experience in information collection
dnsenum The goal of is to do everything possible to collect information about a domain , It can go through Google Or the dictionary file guesses the possible domain name , And reverse query a network segment .
It can query the host address information of the website host 、 Domain name server 、MX record( Function exchange record ), Execute on the domain name server axfr request , And pass Google The script gets the extended domain name information , Extract the subdomain name and query , Calculation C Class address and execute Whois Inquire about , Execute reverse query , Write the address segment to a file
2> Command options
usage :dnsenum [ Options ] [ domain name ]. notes :"-" and "--" The difference between ,"-" Use option shorthand ,"--" Use the option write all .
Options explain
General options
--dnsserver <server> Specify domain name server , Example :
dnsenum --dnsserver 114.114.114.114 baidu.com
--enum Shortcut options , amount to "--threads 5 -s 15 -w", Option description subsequent description
-h --help
Display help information
--noreverse Skip reverse query operation
--nocolor No color output
--private Show and in "domain_ips.txt" Save private at the end of the file ips
--subfile <file> Write all valid subdomain names to the specified file
-t, --timeout <value>
tcp perhaps udp Connection timeout for , The default is 10s( Time unit : second )
--threads <value> Number of query threads
-v, --verbose Show all progress and error messages
Other common options
-o --output <file> Output options , Save the output information to the specified file
-e, --exclude <regexp> Reverse Query options , Exclude from the reverse query results that match the regular expression PTR Record , Very useful for troubleshooting invalid hosts
-w, --whois In a C Segment network address range provided whois Inquire about
For other options not described, please enter :dnsenum -h Inquire about .

3>
dmitry
1> function :
according to IP( Or domain name ) To query the target host Whois Information
stay Netcraft.com Mining host information on the web site
Find the subdomain used in the target domain
Find the e-mail address of the target domain
Probe for open ports on the target host 、 Shielded ports and closed ports
2>
3>
边栏推荐
- USTC of China University of science and technology: Minrui Wang | distribution network voltage stabilization based on transformer Multi-Agent Reinforcement Learning
- [LeetCode]26. Removes duplicates from a sorted array thirty-three
- 2022施工員-設備方向-通用基礎(施工員)操作證考試題及模擬考試
- Binary search the specified number of numbers in the array binary advanced
- How to visit a website
- PMP test difficulty and pass rate
- PMP registration conditions, time, cost, new version related information
- [MRCTF2020]Ez_bypass --BUUCTF
- Transaction creation of btcd transaction process (I)
- Go design concurrent web crawler
猜你喜欢

What occupation is suitable for PMP?

PMP test experience

浏览器缓存的执行流程

测试平台系列(97) 完善执行case部分

A simple deadlock example

PMP renewal | PDU specific operation diagram

Basics of network security (1)

KAUST:Deyao Zhu | 价值记忆图:基于离线强化学习的图结构世界模型

How to control the display and hiding of layergroup through transparency in leaflet

How to visit a website
随机推荐
哲學和文學的區別
[LeetCode]7. Integer inversion thirty-nine
Free lottery --- PMP renewal PDU | PMP knowledge map
TypeError: wave. ensureState is not a function
Solution to the problem of closing the watchdog of STM32 in the sleep mode (stop/standby)
Is the PMP training organization an actual training?
[matlab] symbol calculation
Kaust:deyao Zhu | value memory map: a graph structured world model based on off-line reinforcement learning
Ad14 component pin name disappeared
Go implements concurrent non blocking caching
Matlab [path planning] - UAV drug distribution route optimization
[matlab] basic knowledge
The origin of MySQL in bedtime stories
How to visit a website
String类中split()方法的使用
【HCIE论述】组播IGMP-A
Some basic design knowledge
Maya modeling VI
[hcie discussion] rr-a
如何快速查询手机号码归属地和运营商