DNSENUM
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
dnsenum is a Perl script for DNS enumeration. It discovers hosts, DNS records, subdomains via brute force and Google scraping, performs zone transfers, and maps network ranges.
BASIC USAGE#
dnsenum <domain> # Basic DNS enumeration dnsenum --enum <domain> # Shortcut for common options dnsenum -o output.xml <domain> # Save results in XML format
DNS RECORD ENUMERATION#
dnsenum <domain> # Get A, NS, MX records dnsenum --noreverse <domain> # Skip reverse lookups dnsenum -r <domain> # Enable recursion
ZONE TRANSFER#
dnsenum -z <domain> # Attempt zone transfer (AXFR) dnsenum --noaxfr <domain> # Skip zone transfer attempts
SUBDOMAIN BRUTE FORCE#
dnsenum -f /path/wordlist.txt <domain>
# Brute force with custom wordlist
dnsenum --subfile subs.txt <domain>
# Save discovered subdomains
dnsenum -t 10 <domain> # Set timeout (seconds)
dnsenum --threads 5 <domain> # Set number of threads
GOOGLE SCRAPING#
dnsenum -p 10 <domain> # Scrape 10 Google result pages dnsenum -s 50 <domain> # Max 50 Google scrape results dnsenum --nogscrape <domain> # Disable Google scraping
WHOIS & NETWORK#
dnsenum -w <domain> # Perform whois queries on netranges dnsenum --nowhois <domain> # Skip whois lookups dnsenum -c <domain> # Perform C class network lookups
DNS SERVER OPTIONS#
dnsenum --dnsserver 8.8.8.8 <domain>
# Use specific DNS server
dnsenum --tcp <domain> # Use TCP instead of UDP
OUTPUT OPTIONS#
dnsenum -o results.xml <domain> # Output in XML format dnsenum -v <domain> # Verbose output
COMBINED EXAMPLES#
# Full enumeration with brute force dnsenum --enum -f /usr/share/wordlists/dns.txt -o results.xml example.com # Quick scan with custom DNS server dnsenum --dnsserver 8.8.8.8 --noreverse example.com # Threaded brute force with Google scraping dnsenum --threads 10 -p 5 -s 20 -f subdomains.txt example.com # Zone transfer attempt only dnsenum -z --nogscrape --noreverse example.com
WORDLISTS#
/usr/share/dnsenum/dns.txt # Default dnsenum wordlist
/usr/share/wordlists/dnsmap.txt # Alternative DNS wordlist
/usr/share/seclists/Discovery/DNS/
# SecLists DNS wordlists
NOTES#
- Requires Perl with Net::DNS, Net::IP modules - Google scraping may get blocked after many requests - Zone transfers only work on misconfigured DNS servers - Use --threads for faster brute forcing - XML output useful for importing into other tools