Skip to Content
Practical Web Penetration Testing
book

Practical Web Penetration Testing

by Gus Khawaja
June 2018
Intermediate to advanced
294 pages
7h 5m
English
Packt Publishing
Content preview from Practical Web Penetration Testing

Domain name system – DNS enumeration

DNS enumeration will reveal information regarding domain names and IP addresses assigned to the target, as well as the route between us and the final destination.

In summary, the Domain Name System (DNS) is a database that resolves domain names (for example, google.com) to its IP addresses (172.217.10.46).

You will use the DNS information for the following reasons:

  • To identify whether the DNS server allows a zone transfer. If it does, then it will reveal the hostnames and IP addresses of internet-accessible systems.
  • By using a brute-force methodology, the tool allows us to identify new domain names or subdomains associated with the target.
  • Finding services that may be vulnerable (for example, FTP).
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Hands-On Web Penetration Testing with Metasploit

Hands-On Web Penetration Testing with Metasploit

Harpreet Singh, Himanshu Sharma
Penetration Testing

Penetration Testing

Georgia Weidman

Publisher Resources

ISBN: 9781788624039Supplemental Content