← All cheat sheets

DNSENUM

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

dnsenum is a Perl script for DNS enumeration. It discovers hosts,
DNS records, subdomains via brute force and Google scraping,
performs zone transfers, and maps network ranges.

BASIC USAGE#

dnsenum <domain>                 # Basic DNS enumeration
dnsenum --enum <domain>          # Shortcut for common options
dnsenum -o output.xml <domain>   # Save results in XML format

DNS RECORD ENUMERATION#

dnsenum <domain>                 # Get A, NS, MX records
dnsenum --noreverse <domain>     # Skip reverse lookups
dnsenum -r <domain>              # Enable recursion

ZONE TRANSFER#

dnsenum -z <domain>              # Attempt zone transfer (AXFR)
dnsenum --noaxfr <domain>        # Skip zone transfer attempts

SUBDOMAIN BRUTE FORCE#

dnsenum -f /path/wordlist.txt <domain>
                                 # Brute force with custom wordlist
dnsenum --subfile subs.txt <domain>
                                 # Save discovered subdomains
dnsenum -t 10 <domain>           # Set timeout (seconds)
dnsenum --threads 5 <domain>     # Set number of threads

GOOGLE SCRAPING#

dnsenum -p 10 <domain>           # Scrape 10 Google result pages
dnsenum -s 50 <domain>           # Max 50 Google scrape results
dnsenum --nogscrape <domain>     # Disable Google scraping

WHOIS & NETWORK#

dnsenum -w <domain>              # Perform whois queries on netranges
dnsenum --nowhois <domain>       # Skip whois lookups
dnsenum -c <domain>              # Perform C class network lookups

DNS SERVER OPTIONS#

dnsenum --dnsserver 8.8.8.8 <domain>
                                 # Use specific DNS server
dnsenum --tcp <domain>           # Use TCP instead of UDP

OUTPUT OPTIONS#

dnsenum -o results.xml <domain>  # Output in XML format
dnsenum -v <domain>              # Verbose output

COMBINED EXAMPLES#

# Full enumeration with brute force
dnsenum --enum -f /usr/share/wordlists/dns.txt -o results.xml example.com

# Quick scan with custom DNS server
dnsenum --dnsserver 8.8.8.8 --noreverse example.com

# Threaded brute force with Google scraping
dnsenum --threads 10 -p 5 -s 20 -f subdomains.txt example.com

# Zone transfer attempt only
dnsenum -z --nogscrape --noreverse example.com

WORDLISTS#

/usr/share/dnsenum/dns.txt       # Default dnsenum wordlist
/usr/share/wordlists/dnsmap.txt  # Alternative DNS wordlist
/usr/share/seclists/Discovery/DNS/
                                 # SecLists DNS wordlists

NOTES#

- Requires Perl with Net::DNS, Net::IP modules
- Google scraping may get blocked after many requests
- Zone transfers only work on misconfigured DNS servers
- Use --threads for faster brute forcing
- XML output useful for importing into other tools