How to do it...

We will be using zonetransfer.me as our target domain name. The domain zonetransfer.me has been created by Robin Wood, from DigiNinja (https://digi.ninja/projects/zonetransferme.php), to illustrate the risks of allowing public DNS zone transfers:

  1. We first use whois on the domain name to get the registration information about it. Let's try testing a domain such as zonetransfer.me:
# whois zonetransfer.me
  1. Another tool used to get information about the domain name and DNS resolution is dig. We can, for example, query the nameservers for the target domain:
# dig ns zonetransfer.me
  1. Once we have the information on the DNS servers, ...

Get Kali Linux Web Penetration Testing Cookbook - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.