finding
DNS zone transfer
dig axfr @<dns_server_ip> <domain>fierce --domain zontransfer.meDomain takeover
Subdomain enumeration
gobuster dns -d "$domain" --resolver 10.129.201.127 -w tools/subbrute/names.txt -t 320Enumerate CNAME record
DNS spoofing/cache poisoning (MITM attack)
Last updated