首页 > 其他分享 >kali 子域名搜集工具学习记录

kali 子域名搜集工具学习记录

时间:2022-11-24 10:57:54浏览次数:68  
标签:will dns kali 搜集 域名 DNS fierce pl

# fierce 

主要是对子域名进行扫描和收集信息,并且它还可以测试区域传送漏洞。

 

kali 2022.1 apt-get 安装的fierce并没有 -dns参数,需要手动下载,下载后有个fierce.pl 文件

下载地址

安装后,用perl fierce.pl -h 可以看到下面的信息,多出来了-dns

└─$ perl fierce.pl -h |more
fierce.pl (C) Copywrite 2006,2007 - By RSnake at http://ha.ckers.org/fierce/

    Usage: perl fierce.pl [-dns example.com] [OPTIONS]

Overview:
    Fierce is a semi-lightweight scanner that helps locate non-contiguous
    IP space and hostnames against specified domains.  It's really meant
    as a pre-cursor to nmap, unicornscan, nessus, nikto, etc, since all 
    of those require that you already know what IP space you are looking 
    for.  This does not perform exploitation and does not scan the whole 
    internet indiscriminately.  It is meant specifically to locate likely 
    targets both inside and outside a corporate network.  Because it uses 
    DNS primarily you will often find mis-configured networks that leak 
    internal address space. That's especially useful in targeted malware.

Options:
    -connect    Attempt to make http connections to any non RFC1918
        (public) addresses.  This will output the return headers but
        be warned, this could take a long time against a company with
        many targets, depending on network/machine lag.  I wouldn't
        recommend doing this unless it's a small company or you have a
        lot of free time on your hands (could take hours-days).  
        Inside the file specified the text "Host:\n" will be replaced
        by the host specified. Usage:

    perl fierce.pl -dns example.com -connect headers.txt

    -delay        The number of seconds to wait between lookups.
    -dns        The domain you would like scanned.
    -dnsfile      Use DNS servers provided by a file (one per line) for
                reverse lookups (brute force).
    -dnsserver    Use a particular DNS server for reverse lookups 
        (probably should be the DNS server of the target).  Fierce
        uses your DNS server for the initial SOA query and then uses
        the target's DNS server for all additional queries by default.
    -file        A file you would like to output to be logged to.
    -fulloutput    When combined with -connect this will output everything
        the webserver sends back, not just the HTTP headers.
    -help        This screen.
    -nopattern    Don't use a search pattern when looking for nearby
        hosts.  Instead dump everything.  This is really noisy but
        is useful for finding other domains that spammers might be
        using.  It will also give you lots of false positives, 
        especially on large domains.
View Code

但是,-domain 有没有了,所以最好两个版本都保留,为了方便使用可以做个软连接.

 

# dnsenum

dnsenum <域名> 

-f <file>

主机地址信息、域名服务器、mx reccord(交换记录),在域名上执行axfr请求

 

# dnswalk <域名>

判断域名所对应的服务器是否存在DNS Zone transfers漏洞

 

标签:will,dns,kali,搜集,域名,DNS,fierce,pl
From: https://www.cnblogs.com/Cong0ks/p/16921117.html

相关文章

  • kali 安装 checkra1n
    echo"debhttps://assets.checkra.in/debian/"|sudotee-a/etc/apt/sources.listsudoapt-keyadv--fetch-keyshttps://assets.checkra.in/debian/archive.keyap......
  • webpack配置不同环境域名进行映射访问
    前言:前端开发经常会不同环境进行测试和开发等,如dev和uat的环境数据有差异,或者代码有略微不同,都会导致前端开发在调试不同环境的Bug时可能需要访问不同域名,此时我们可以通......
  • kali linux 2022.1版本root密码重置
    1、按e进入修复模式2、在linux行尾输入rwsingleinit=/bin/bash3、Ctrl+x进入命令行界面4、使用passwd命令修改root密码,完成后重启5、使用root用户登录6、重置成功......
  • kali 1、信息收集-ZoomEye(钟馗之眼)
    ZoomEye(钟馗之眼)是知道创宇公司研发的一款网络空间搜索引擎。侧重点在web服务层面。1、需要注册用户注册后成为终身会员每月API可享1万条搜索服务。2、搜索语法说......
  • 申请免费证书、域名解析以及nginx部署配置https为微信小程序服务
    申请免费证书、域名解析以及nginx部署配置https为微信小程序服务 时间:2022.11.23 作者:飞快的蜗牛  关键字:申请免费证书、域名解析、nginx配置部署https......
  • nginx配置反向代理及根据域名设置不同的反向代理
    参考以下配置nginx.confhttp{#配置反向代理服务器upstreamserver1{server127.0.0.1:8000;}server{listen443ssl;......
  • CodeForces - 320E Kalila and Dimna in the Logging Industry
    题意:你有要拿一把锯子砍树。锯子有有电和没电两个状态,只有在有电的时候才能工作,每次工作都可以砍1单位高度的树,然后就会没电。没电后要充电才能工作。充电有代价,代价为,当前......
  • 搜集糖果
     搜集糖果(candy)【题目描述】在一片N*M的四连通(一个点与它上方、下方、左方、右方这四个点连通)田野中,散布着很多很多的糖果。Ryz现在要以(x,y)为起点去搜集糖果。Ryz搜......
  • Nginx配置多个域名以及一个域名多个端口
    转:Nginx配置多个域名以及一个域名多个端口 域名后边带着端口如何设置? ......
  • 学院域名解析系统(DNS)说明来自博奥智源公司
    序号货物名称品牌型号技术参数、配置及服务要求1DNS系统网瑞达WRD-ITMS-DNS-H1.支持双机负载均衡方式工作,本次需要实现双机负载均衡方式;2.......