Ultimate DNSrecon Cheat Sheet
Ultimate DNSrecon Cheat Sheet
DNS enumeration and reconnaissance tool. Discover subdomains, records, zone transfers, and DNS misconfigurations.
1. Basic Enumeration
Standard DNS enumeration and record discovery.
Basic Domain Scan
dnsrecon -d example.com
Verbose Output
dnsrecon -d example.com -v
Save to File
dnsrecon -d example.com --xml output.xml
Save as JSON
dnsrecon -d example.com --json output.json
Save as CSV
dnsrecon -d example.com --csv output.csv
Save to Database
dnsrecon -d example.com --db output.db
Basic Flags
-d <domain>: Target domain-v: Verbose mode--xml <file>: XML output--json <file>: JSON output--csv <file>: CSV output
Output Options
--db <file>: SQLite database--iw: Continue on error--disable_check_recursion--disable_check_bindversion
2. Record Types
All Record Types (Default)
dnsrecon -d example.com
Specific Record Types
dnsrecon -d example.com -t A,AAAA,MX,NS,SOA,TXT
A Records Only
dnsrecon -d example.com -t A
MX Records
dnsrecon -d example.com -t MX
NS Records
dnsrecon -d example.com -t NS
TXT Records (SPF/DKIM)
dnsrecon -d example.com -t TXT
SRV Records
dnsrecon -d example.com -t SRV
| Record Type | Description | Use Case |
|---|---|---|
A | IPv4 address | Host discovery |
AAAA | IPv6 address | IPv6 mapping |
MX | Mail server | Email infrastructure |
NS | Name server | DNS infrastructure |
SOA | Start of authority | Zone information |
TXT | Text records | SPF, DKIM, DMARC |
SRV | Service records | Service discovery |
CNAME | Canonical name | Alias resolution |
PTR | Pointer record | Reverse DNS |
CAA | Certificate authority | Certificate policy |
Pro Tip: Record Analysis
TXT records often contain valuable information:
This reveals email security configuration and service integrations.
TXT records often contain valuable information:
dnsrecon -d example.com -t TXT | grep -E "spf|dkim|dmarc|google-site"This reveals email security configuration and service integrations.
3. Zone Transfers
Zone Transfer Test
dnsrecon -d example.com -t axfr
Zone Transfer with Specific Server
dnsrecon -d example.com -t axfr -n ns1.example.com
Zone Walk (DNSSEC)
dnsrecon -d example.com -t zonewalk
Check All NS for Zone Transfer
dnsrecon -d example.com -t axfr --threads 10
Reverse Lookup Zone Transfer
dnsrecon -r 192.168.1.0/24 -t axfr
Zone Transfer Types
-t axfr: Full zone transfer-t zonewalk: DNSSEC zone walk-r <range>: Reverse zone-n <server>: Specific NS
Zone Transfer Info
- Reveals all subdomains
- Shows internal structure
- Identifies hidden hosts
- Maps network topology
Warning:
Zone transfers are misconfigurations. Always test all name servers:
dnsrecon -d example.com -t ns
Then test each NS for zone transfer:
dnsrecon -d example.com -t axfr -n ns1.example.com
4. Brute Force
Basic Brute Force
dnsrecon -d example.com -t brt
With Custom Wordlist
dnsrecon -d example.com -t brt -D /path/to/wordlist.txt
With Thread Control
dnsrecon -d example.com -t brt -D wordlist.txt --threads 20
Brute Force with Output
dnsrecon -d example.com -t brt -D wordlist.txt --csv results.csv
Google Enumeration
dnsrecon -d example.com -t goo
Bing Enumeration
dnsrecon -d example.com -t bing
Brute Force Types
-t brt: Brute force subdomains-t goo: Google search-t bing: Bing search-t yand: Yandex search-t crt: Certificate search
Wordlist Options
-D <file>: Custom wordlist--threads <num>: Thread count--tcp: TCP queries--lifetime <sec>: Query timeout
Pro Tip: Wordlists
Use comprehensive wordlists for better results:
Use comprehensive wordlists for better results:
-D /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-5000.txt-D /usr/share/wordlists/SecLists/Discovery/DNS/dns-Jhaddix.txt-D /usr/share/wordlists/SecLists/Discovery/DNS/namelist.txt
5. Advanced Features
Reverse DNS Lookup
dnsrecon -r 192.168.1.0/24
Reverse DNS with Name
dnsrecon -r 192.168.1.1-192.168.1.254 -n 8.8.8.8
DNSSEC Check
dnsrecon -d example.com -t dnssEC
Cache Snooping
dnsrecon -d example.com -t snoop -n 8.8.8.8
BIND Version Check
dnsrecon -d example.com -t bv
Custom DNS Server
dnsrecon -d example.com -n 8.8.8.8
| Flag | Description | Example |
|---|---|---|
-r <range> | Reverse DNS range | -r 192.168.1.0/24 |
-n <server> | Custom DNS server | -n 8.8.8.8 |
-t dnssEC | DNSSEC check | -t dnssEC |
-t snoop | Cache snooping | -t snoop |
-t bv | BIND version | -t bv |
--tcp | TCP queries | --tcp |
--lifetime | Query timeout | --lifetime 10 |
6. Automation Scripts
Complete DNS Enumeration
#!/bin/bash
# dns-enum.sh - Complete DNS enumeration
DOMAIN=$1
OUTPUT_DIR="dns-recon-$DOMAIN"
mkdir -p $OUTPUT_DIR
echo "[+] Basic enumeration..."
dnsrecon -d $DOMAIN --json $OUTPUT_DIR/basic.json
echo "[+] Zone transfer test..."
dnsrecon -d $DOMAIN -t axfr --xml $OUTPUT_DIR/zonetransfer.xml
echo "[+] Brute force subdomains..."
dnsrecon -d $DOMAIN -t brt -D /usr/share/wordlists/subdomains.txt --csv $OUTPUT_DIR/bruteforce.csv
echo "[+] DNSSEC check..."
dnsrecon -d $DOMAIN -t dnssEC --json $OUTPUT_DIR/dnssec.json
echo "[+] Complete! Results in $OUTPUT_DIR/"
Multi-Domain Scanner
#!/bin/bash
# multi-scan.sh - Scan multiple domains
while read -r domain; do
echo "[+] Scanning $domain..."
dnsrecon -d "$domain" --json "results-$domain.json"
# Extract subdomains
jq -r '.[].name' "results-$domain.json" | sort -u > "subdomains-$domain.txt"
echo "[+] Found $(wc -l < subdomains-$domain.txt) subdomains"
done < domains.txt
Zone Transfer Monitor
#!/bin/bash
# zone-monitor.sh - Monitor for zone transfer vulnerabilities
DOMAIN=$1
while true; do
echo "[+] Testing zone transfer for $DOMAIN..."
dnsrecon -d "$DOMAIN" -t axfr --xml results.xml
if grep -q "Zone Transfer" results.xml; then
echo "[!] Zone transfer successful!"
# Send notification
notify "Zone transfer found for $DOMAIN"
fi
sleep 86400
done
Reverse DNS Mapper
#!/bin/bash
# reverse-map.sh - Map reverse DNS
RANGE=$1
OUTPUT="reverse-dns.txt"
echo "[+] Mapping reverse DNS for $RANGE..."
dnsrecon -r "$RANGE" --json results.json
# Extract PTR records
jq -r '.[] | select(.type == "PTR") | "\(.name) -> \(.address)"' results.json > "$OUTPUT"
echo "[+] Results saved to $OUTPUT"
cat "$OUTPUT"
DNS Security Audit
#!/bin/bash
# dns-audit.sh - DNS security audit
DOMAIN=$1
REPORT="dns-audit-$DOMAIN.txt"
echo "DNS Security Audit for $DOMAIN" > "$REPORT"
echo "================================" >> "$REPORT"
echo "[+] Checking DNSSEC..."
dnsrecon -d "$DOMAIN" -t dnssEC >> "$REPORT"
echo "[+] Checking BIND version..."
dnsrecon -d "$DOMAIN" -t bv >> "$REPORT"
echo "[+] Testing zone transfer..."
dnsrecon -d "$DOMAIN" -t axfr >> "$REPORT"
echo "[+] Checking cache snooping..."
dnsrecon -d "$DOMAIN" -t snoop >> "$REPORT"
echo "[+] Audit complete! Report: $REPORT"
Pro Tip: DNS Security Checks
Regularly audit DNS configuration:
1. Test zone transfers on all NS
2. Check DNSSEC implementation
3. Verify BIND version disclosure
4. Test cache snooping vulnerability
5. Review SPF/DKIM/DMARC records
Post a Comment